Red Hat Product Errata RHSA-2026:39009 - Security Advisory Issued: 2026-07-13 Updated: 2026-07-13 RHSA-2026:39009 - Security Advisory Overview Updated Packages Synopsis Important: compat-openssl11 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for compat-openssl11 is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries from the 1.1.1 version and is provided for compatibility with previous releases. Security Fix(es): openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390) openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2456314 - CVE-2026-28390 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing BZ - 2481898 - CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() CVEs CVE-2026-28390 CVE-2026-45447 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 x86_64 compat-openssl11-1.1.1k-5.el9_4.3.i686.rpm SHA-256: 78dcc120d2d8e22094ea493bda03a210567b0877f399078645666801b7a73154 compat-openssl11-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: 6358b7d3d3007494e1e18e3ecdf065fc29eb1ec03ae776d525c0fa4aa74ffcb3 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.i686.rpm SHA-256: 0eab2e6347bde9a68ec098bb65169a83448e9870ceb0e18872d4a52b801bacb6 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: d16ed5203cd3352753c6397239e4c754bfaaca9f3c754ca64a176ca669a37225 compat-openssl11-debugsource-1.1.1k-5.el9_4.3.i686.rpm SHA-256: d1901fa112c31796c53d61de7163d4d31a6c784aa10ddc7f88c850fd180b250a compat-openssl11-debugsource-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: b94d863fa829ca1f50396ffc8bb2f7f1cf6bc1d7df7c14eda4a117cad4b10778 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 ppc64le compat-openssl11-1.1.1k-5.el9_4.3.ppc64le.rpm SHA-256: efa06f74ce7e04bfd545b2d5d21d2b502f0a6596c04b172ecee4d45f3ee604bf compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.ppc64le.rpm SHA-256: 944761ecdd6de1c758db8c836979f56716be7716c70b51d2c80fa3cd84f8579d compat-openssl11-debugsource-1.1.1k-5.el9_4.3.ppc64le.rpm SHA-256: 9ea2179b5f46341539ae9ecf2f39a3b36a737095fa74f8ca79dce65afa01974b Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 x86_64 compat-openssl11-1.1.1k-5.el9_4.3.i686.rpm SHA-256: 78dcc120d2d8e22094ea493bda03a210567b0877f399078645666801b7a73154 compat-openssl11-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: 6358b7d3d3007494e1e18e3ecdf065fc29eb1ec03ae776d525c0fa4aa74ffcb3 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.i686.rpm SHA-256: 0eab2e6347bde9a68ec098bb65169a83448e9870ceb0e18872d4a52b801bacb6 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: d16ed5203cd3352753c6397239e4c754bfaaca9f3c754ca64a176ca669a37225 compat-openssl11-debugsource-1.1.1k-5.el9_4.3.i686.rpm SHA-256: d1901fa112c31796c53d61de7163d4d31a6c784aa10ddc7f88c850fd180b250a compat-openssl11-debugsource-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: b94d863fa829ca1f50396ffc8bb2f7f1cf6bc1d7df7c14eda4a117cad4b10778 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 aarch64 compat-openssl11-1.1.1k-5.el9_4.3.aarch64.rpm SHA-256: 3df28a3dcbb2d463d167c21d9b199279f8f579feabefdf1092017edf12374d77 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.aarch64.rpm SHA-256: fe02d6a7fabf58ae1510d574fc8714e15ca5893d0d6f232f4fd7f834c213c8a7 compat-openssl11-debugsource-1.1.1k-5.el9_4.3.aarch64.rpm SHA-256: 8bcb113195a1d7e62d9c9ca34c1338e86e41c9e8425c281d3ab99a2cb9085104 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 s390x compat-openssl11-1.1.1k-5.el9_4.3.s390x.rpm SHA-256: 318d1919dc7890225fe725c17e204659f8d8aff07fee38d850d81c5cd0494cc7 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.s390x.rpm SHA-256: e211519225b4d5a3fdbc14c3ada43bbbf6a568ca57eb6e999a4b7a606e2da1e9 compat-openssl11-debugsource-1.1.1k-5.el9_4.3.s390x.rpm SHA-256: 816d75372c84a312373468bbf656e360c490a3245f8feb7cc0efb18658cdc782 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 x86_64 compat-openssl11-1.1.1k-5.el9_4.3.i686.rpm SHA-256: 78dcc120d2d8e22094ea493bda03a210567b0877f399078645666801b7a73154 compat-openssl11-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: 6358b7d3d3007494e1e18e3ecdf065fc29eb1ec03ae776d525c0fa4aa74ffcb3 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.i686.rpm SHA-256: 0eab2e6347bde9a68ec098bb65169a83448e9870ceb0e18872d4a52b801bacb6 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: d16ed5203cd3352753c6397239e4c754bfaaca9f3c754ca64a176ca669a37225 compat-openssl11-debugsource-1.1.1k-5.el9_4.3.i686.rpm SHA-256: d1901fa112c31796c53d61de7163d4d31a6c784aa10ddc7f88c850fd180b250a compat-openssl11-debugsource-1.1.1k-5.el9_4.3.x86_64.rpm SHA-256: b94d863fa829ca1f50396ffc8bb2f7f1cf6bc1d7df7c14eda4a117cad4b10778 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 aarch64 compat-openssl11-1.1.1k-5.el9_4.3.aarch64.rpm SHA-256: 3df28a3dcbb2d463d167c21d9b199279f8f579feabefdf1092017edf12374d77 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.aarch64.rpm SHA-256: fe02d6a7fabf58ae1510d574fc8714e15ca5893d0d6f232f4fd7f834c213c8a7 compat-openssl11-debugsource-1.1.1k-5.el9_4.3.aarch64.rpm SHA-256: 8bcb113195a1d7e62d9c9ca34c1338e86e41c9e8425c281d3ab99a2cb9085104 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 ppc64le compat-openssl11-1.1.1k-5.el9_4.3.ppc64le.rpm SHA-256: efa06f74ce7e04bfd545b2d5d21d2b502f0a6596c04b172ecee4d45f3ee604bf compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.ppc64le.rpm SHA-256: 944761ecdd6de1c758db8c836979f56716be7716c70b51d2c80fa3cd84f8579d compat-openssl11-debugsource-1.1.1k-5.el9_4.3.ppc64le.rpm SHA-256: 9ea2179b5f46341539ae9ecf2f39a3b36a737095fa74f8ca79dce65afa01974b Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 SRPM compat-openssl11-1.1.1k-5.el9_4.3.src.rpm SHA-256: c4c081d93b5b60a154f8dd26d294a5fd486dc11be91da7e244da0137103044b0 s390x compat-openssl11-1.1.1k-5.el9_4.3.s390x.rpm SHA-256: 318d1919dc7890225fe725c17e204659f8d8aff07fee38d850d81c5cd0494cc7 compat-openssl11-debuginfo-1.1.1k-5.el9_4.3.s390x.rpm SHA-256: e211519225b4d5a3fdbc14c3ada43bbbf6a568ca57eb6e999a4b7a606e2da1e9 compat-openssl11-debugsource-1.1.1k-5.el9_4.3.s390x.rpm SHA-256: 816d75372c84a312373468bbf656e360c490a3245f8feb7cc0efb18658cdc782 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
The compat-openssl11 package for RHEL 9.4 is affected by two high-severity vulnerabilities: a NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390, CVSS 7.5) leading to Denial of Service, and a heap use-after-free in PKCS7_verify() (CVE-2026-45447, CVSS 8.8). The affected version range for the OpenSSL 1.1.1 branch is from 1.1.1 up to, but not including, versions 1.1.1zg for CVE-2026-28390 and 1.1.1zh for CVE-2026-45447. Red Hat has released an update to compat-openssl11 version 1.1.1k-5.el9_4.3 to address these issues.