CVE-2022-0778
📛 CVE Title
Dell PowerStoreOS: CVE-2022-0778: DSA-2024-158: Dell PowerStore X Security Update for Multiple Vulnerabilities
Description
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- MEDIUM
- CVSS score
- 5.0 / 10
- CVSS vector
AV:N/AC:L/Au:N/C:N/I:N/A:P- Effective score
- 5.0 / 10 MEDIUM source: CNA overview
- MSRC score
- 7.5 / 10 HIGH
- CWE(s)
-
CWE-835 - Reserved
- —
- Published
- 2024-04-04 00:00 UTC
- Last updated
- 2026-02-21 02:30 UTC
- Source
- https://www.rapid7.com/db/vulnerabilities/dell-powerstore-dsa2024158-cve-2022-0778/
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2022-03-15 17:15:08 UTC
- NVD last modified
- 2026-05-22 14:16:19 UTC
- NVD CVSS v3.1
- 7.5 / 10 HIGH source: nvd@nist.gov
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.0754 (probability of exploitation in next 30 days)
- EPSS percentile
- 91.97% vs all CVEs — higher = more likely to be exploited, as of 2026-06-08
NVD / KEV / EPSS data refreshed 2026-06-09 11:25 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2022-1575 - Assigner
- openssl
- Published
- Mar 15, 2022, 5:05:20 PM
- Updated
- May 22, 2026, 1:28:08 PM
- EUVD base score (CVSS 3.1)
-
7.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EUVD-reported EPSS
- 70.5600
- Vendors
- OpenSSL
- Products
-
OpenSSL (Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc))OpenSSL (Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1))OpenSSL (Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m))
- Aliases
-
GHSA-x3mh-jvjw-3xwx
ENISA description: The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
EUVD references (29)
- https://www.openssl.org/news/secadv/20220315.txt
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83
- https://www.debian.org/security/2022/dsa-5103
- https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html
- https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://security.netapp.com/advisory/ntap-20220321-0002/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002
- https://www.tenable.com/security/tns-2022-06
- https://www.tenable.com/security/tns-2022-07
- https://www.tenable.com/security/tns-2022-08
- http://seclists.org/fulldisclosure/2022/May/33
- http://seclists.org/fulldisclosure/2022/May/35
- http://seclists.org/fulldisclosure/2022/May/38
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://support.apple.com/kb/HT213257
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213255
- https://www.tenable.com/security/tns-2022-09
- https://security.netapp.com/advisory/ntap-20220429-0005/
- http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf
- https://security.gentoo.org/glsa/202210-02
- https://security.netapp.com/advisory/ntap-20240621-0006/
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-09-25 03:01 UTC (source: CVRF).
- MS CVSS base score
- 7.5 / 10 (temporal 7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - Release
- 2024-Sep
Microsoft remediations / KB articles (3)
- openssl — Vendor Fix / CBL-Mariner (fixed build 1.1.1k-9)
- https://nvd.nist.gov/vuln/detail/CVE-2022-0778 — None Available / openssl
- edk2 — Vendor Fix / CBL-Mariner (fixed build 20240223gitedc6681206c1-2)
Affected products — CPE 2.3 (19) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:*cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:*cpe:2.3:a:netapp:santricity_smi-s_provider:-:*:*:*:*:*:*:*cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:netapp:a250:-:*:*:*:*:*:*:*cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:netapp:500f:-:*:*:*:*:*:*:*cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
MITRE references (25) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
- http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html
- 20220516 APPLE-SA-2022-05-16-4 Security Update 2022-004 Catalina mailing-list
- 20220516 APPLE-SA-2022-05-16-3 macOS Big Sur 11.6.6 mailing-list
- 20220516 APPLE-SA-2022-05-16-2 macOS Monterey 12.4 mailing-list
- https://www.tenable.com/security/tns-2022-08
- https://www.tenable.com/security/tns-2022-07
- https://www.tenable.com/security/tns-2022-06
- https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://security.netapp.com/advisory/ntap-20220429-0005/
- https://www.tenable.com/security/tns-2022-09
- GLSA-202210-02 vendor-advisory
- [debian-lts-announce] 20220317 [SECURITY] [DLA 2953-1] openssl1.0 security update mailing-list
- FEDORA-2022-9e88b5d8d7 vendor-advisory
- FEDORA-2022-a5f51502f0 vendor-advisory
- FEDORA-2022-8bb51f6901 vendor-advisory
- DSA-5103 vendor-advisory
- https://www.openssl.org/news/secadv/20220315.txt
- https://security.netapp.com/advisory/ntap-20220321-0002/
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246
- [debian-lts-announce] 20220317 [SECURITY] [DLA 2952-1] openssl security update mailing-list
Web references (34)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- MSRC update guide: CVE-2022-0778 msrc
- None Available msrc
- https://my.f5.com/manage/s/article/K31323265 rapid7:my.f5.com
- https://errata.rockylinux.org/RLSA-2022:4899 rapid7:errata.rockylinux.org
- https://errata.rockylinux.org/RLSA-2022:5326 rapid7:errata.rockylinux.org
- https://errata.rockylinux.org/RLSA-2022:1065 rapid7:errata.rockylinux.org
- https://aix.software.ibm.com/aix/efixes/security/openssl_advisory35.asc rapid7:aix.software.ibm.com
- https://support.apple.com/kb/HT213255 rapid7:support.apple.com
- https://support.apple.com/kb/HT213257 rapid7:support.apple.com
- https://support.apple.com/kb/HT213256 rapid7:support.apple.com
- https://errata.almalinux.org/8/ALSA-2022-5326.html rapid7:errata.almalinux.org
- https://errata.almalinux.org/8/ALSA-2022-1065.html rapid7:errata.almalinux.org
- https://forums.ivanti.com/s/article/CVE-2022-0778-OpenSSL-Vulnerability-may-lead-to-DoS-attack?language=en_US rapid7:forums.ivanti.com
- https://security.alpinelinux.org/vuln/CVE-2022-0778 rapid7:security.alpinelinux.org
- https://support.hpe.com/hpsc/doc/public/display?docId=hpesbhf04366en_us&docLocale=en_US rapid7:support.hpe.com
- https://www.arista.com//en/support/advisories-notices/security-advisory/15438-security-advisory-0075 rapid7:www.arista.com
- https://security.paloaltonetworks.com/CVE-2022-0778 rapid7:security.paloaltonetworks.com
- https://csaf.arubanetworking.hpe.com/2022/hpe_aruba_networking_-_2022-009.json rapid7:csaf.arubanetworking.hpe.com
- https://nvd.nist.gov/vuln/detail/CVE-2022-0778 rapid7:nvd.nist.gov
- https://alas.aws.amazon.com/AL2023/ALAS-2023-037.html rapid7:alas.aws.amazon.com
- https://alas.aws.amazon.com/AL2023/ALAS-2023-051.html rapid7:alas.aws.amazon.com
- https://security.paloaltonetworks.com/json/CVE-2022-0778 rapid7:security.paloaltonetworks.com
- https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2022-0778 rapid7:services.nvd.nist.gov
- https://www.fortiguard.com/psirt/FG-IR-22-059 rapid7:www.fortiguard.com
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0778 rapid7:cve.mitre.org
- http://issue.In rapid7:issue.in
- https://www.autodesk.com/trust/security-advisories/ADSK-SA-2022-0016 rapid7:www.autodesk.com
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002 rapid7:psirt.global.sonicwall.com
- https://www.dell.com/support/kbdoc/en-us/000200644/dsa-2022-154-dell-idrac8-and-dell-idrac9-security-update-for-an-openssl-vulnerability rapid7:www.dell.com
- https://www.cve.org/CVERecord?id=CVE-2022-0778 rapid7:www.cve.org
- http://cwe.mitre.org/data/definitions/835.html rapid7:cwe.mitre.org
- https://www.dell.com/support/kbdoc/en-us/000223810/dsa-2024-158-dell-powerstore-x-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1575 rapid7:euvd.enisa.europa.eu
- https://attackerkb.com/topics/CVE-2022-0778 rapid7:attackerkb.com
NVD-tagged references (63)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html openssl-security@openssl.org Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html af854a3a-2127-422b-91ae-364da2661108 Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2022/May/33 openssl-security@openssl.org Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/33 af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/35 openssl-security@openssl.org Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/35 af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/38 openssl-security@openssl.org Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/38 af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf openssl-security@openssl.org Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html openssl-security@openssl.org Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html openssl-security@openssl.org Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002 openssl-security@openssl.org Third Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://security.gentoo.org/glsa/202210-02 openssl-security@openssl.org Third Party Advisory
- https://security.gentoo.org/glsa/202210-02 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220321-0002/ openssl-security@openssl.org Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220321-0002/ af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220429-0005/ openssl-security@openssl.org Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220429-0005/ af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://support.apple.com/kb/HT213255 openssl-security@openssl.org Third Party Advisory
- https://support.apple.com/kb/HT213255 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://support.apple.com/kb/HT213256 openssl-security@openssl.org Third Party Advisory
- https://support.apple.com/kb/HT213256 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://support.apple.com/kb/HT213257 openssl-security@openssl.org Third Party Advisory
- https://support.apple.com/kb/HT213257 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.debian.org/security/2022/dsa-5103 openssl-security@openssl.org Third Party Advisory
- https://www.debian.org/security/2022/dsa-5103 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.openssl.org/news/secadv/20220315.txt openssl-security@openssl.org Vendor Advisory
- https://www.openssl.org/news/secadv/20220315.txt af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html openssl-security@openssl.org Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html openssl-security@openssl.org Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.tenable.com/security/tns-2022-06 openssl-security@openssl.org Third Party Advisory
- https://www.tenable.com/security/tns-2022-06 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.tenable.com/security/tns-2022-07 openssl-security@openssl.org Third Party Advisory
- https://www.tenable.com/security/tns-2022-07 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.tenable.com/security/tns-2022-08 openssl-security@openssl.org Third Party Advisory
- https://www.tenable.com/security/tns-2022-08 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.tenable.com/security/tns-2022-09 openssl-security@openssl.org Third Party Advisory
- https://www.tenable.com/security/tns-2022-09 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-019200.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://cert-portal.siemens.com/productcert/html/ssa-028723.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://cert-portal.siemens.com/productcert/html/ssa-108696.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://cert-portal.siemens.com/productcert/html/ssa-712929.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65 openssl-security@openssl.org
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65 af854a3a-2127-422b-91ae-364da2661108
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83 openssl-security@openssl.org
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83 af854a3a-2127-422b-91ae-364da2661108
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246 openssl-security@openssl.org
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246 af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/ openssl-security@openssl.org
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/ openssl-security@openssl.org
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/ openssl-security@openssl.org
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/ af854a3a-2127-422b-91ae-364da2661108
- https://security.netapp.com/advisory/ntap-20240621-0006/ openssl-security@openssl.org
- https://security.netapp.com/advisory/ntap-20240621-0006/ af854a3a-2127-422b-91ae-364da2661108
Remediations (5)
-
rapid7
openssl-upgrade-latest
2026-05-29 03:29 UTC -
rapid7
f5-big-ip-upgrade-latest
2026-05-29 02:52 UTC -
rapid7
debian-upgrade-openssl
2026-05-29 02:47 UTC -
rapid7
amazon-linux-upgrade-openssl
2026-05-29 01:31 UTC -
rapid7
ibm-aix-openssl_advisory35
2026-05-28 22:34 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.