openssl3 Info

openssl3 was added to epel8 repo on 2021-11-18
Page updated: 2024-04-20 17:48
Repo Status - Overall Status

Source NVR: openssl3-3.0.7-5.el8.1 (2022-03-25)

Binary Packages

openssl3 openssl3-3.0.7-5.el8.1
openssl3-devel openssl3-devel-3.0.7-5.el8.1
openssl3-libs openssl3-libs-3.0.7-5.el8.1

Bugs

2182590 NEW CVE-2023-0465 openssl3: openssl: Invalid certificate policies in leaf certificates are silently ignored [epel-8]
2182602 NEW CVE-2023-0466 openssl3: openssl: Certificate policy check not enabled [epel-8]
2188526 NEW CVE-2023-1255 openssl3: openssl: Input buffer over-read in AES-XTS implementation on 64 bit ARM [epel-8]
2211109 NEW CVE-2023-2650 openssl3: openssl: Possible DoS translating ASN.1 object identifiers [epel-8]
2223821 NEW TRIAGE-CVE-2023-2975 openssl3: openSSL: AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries [epel-8]
2228050 NEW CVE-2023-3817 openssl3: OpenSSL: Excessive time spent checking DH q parameter value [epel-all]
2248621 NEW CVE-2023-5678 openssl3: openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow [epel-8]
2249063 NEW CVE-2023-5363 openssl3: openssl: Incorrect cipher key and IV length processing [epel-8]
2257573 NEW CVE-2023-6129 openssl3: openssl: POLY1305 MAC implementation corrupts vector registers on PowerPC [epel-all]
2258505 NEW CVE-2023-6237 openssl3: openssl: Excessive time spent checking invalid RSA public keys [epel-all]
2259950 NEW TRIAGE CVE-2024-0727 openssl3: openssl: denial of service via null dereference [epel-all]
2274021 NEW TRIAGE CVE-2024-2511 openssl3: openssl: Unbounded memory growth with session handling in TLSv1.3 [epel-all]
2276143 NEW openssl3 epel-8 SIGILL on ppc64le Power8

Install Failures