gpp_maybe Security update for openssl-3
SUSE-SLE-Micro-5.3-2026-4032


This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837).


cloud_download Downloads

SUSE Linux Enterprise Micro 5.3 s390x
  • Packages
    libopenssl3
    Secure Sockets and Transport Layer Security
    3.0.8-150400.4.98.1 lock rpm
    openssl-3
    Secure Sockets and Transport Layer Security
    3.0.8-150400.4.98.1 lock src
SUSE Linux Enterprise Micro 5.3 aarch64
  • Packages
    libopenssl3
    Secure Sockets and Transport Layer Security
    3.0.8-150400.4.98.1 lock rpm
    openssl-3
    Secure Sockets and Transport Layer Security
    3.0.8-150400.4.98.1 lock src
SUSE Linux Enterprise Micro 5.3 x86_64
  • Packages
    libopenssl3
    Secure Sockets and Transport Layer Security
    3.0.8-150400.4.98.1 lock rpm
    openssl-3
    Secure Sockets and Transport Layer Security
    3.0.8-150400.4.98.1 lock src