gpp_maybe
Security update for openssl-3
SUSE-SLE-Micro-5.3-2026-4032
This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837).
-
Release DateSep 7 2026
-
ReferencesBugzilla: 1274774, 1274788, 1274790, 1274795, 1274797, 1275837
CVEs: CVE-2026-54874, CVE-2026-63072, CVE-2026-63074, CVE-2026-63076, CVE-2026-75803 -
Typesecurity
-
Severityimportant
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Linux Enterprise Micro 5.3 s390x
-
Packageslibopenssl3
Secure Sockets and Transport Layer Securityopenssl-33.0.8-150400.4.98.1 lock rpm
Secure Sockets and Transport Layer Security3.0.8-150400.4.98.1 lock src
SUSE Linux Enterprise Micro 5.3 aarch64
-
Packageslibopenssl3
Secure Sockets and Transport Layer Securityopenssl-33.0.8-150400.4.98.1 lock rpm
Secure Sockets and Transport Layer Security3.0.8-150400.4.98.1 lock src
SUSE Linux Enterprise Micro 5.3 x86_64
-
Packageslibopenssl3
Secure Sockets and Transport Layer Securityopenssl-33.0.8-150400.4.98.1 lock rpm
Secure Sockets and Transport Layer Security3.0.8-150400.4.98.1 lock src