CVE-2026-28390

high
Published 2026-04-07 Β· Modified 2026-06-03
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
7.5

Description

Moderate: compat-openssl11 security update

Predictions

Exploit likelihood
83%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing Red Hat statement This CVE has been rated as moderate by redhat because the vulnerability is limited to a denial-of-service condition caused by a NULL pointer dereference in OpenSSL CMS processing, without evidence of memory corruption or code execution, furthermore the Affected…

Description

openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

Red Hat statement

This CVE has been rated as moderate by redhat because the vulnerability is limited to a denial-of-service condition caused by a NULL pointer dereference in OpenSSL CMS processing, without evidence of memory corruption or code execution, furthermore the Affected functionality is niche. The vulnerable path requires: CMS/S/MIME processing, specifically CMS_decrypt(), with RSA-OAEP KeyTransportRecipientInfo. Many OpenSSL consumers never use CMS APIs, never process S/MIME, or do not decrypt attacker-controlled CMS objects. So exposure is far narrower than a generic TLS parsing vulnerability.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Discovery 2discovery/discovery-server-rhel9:1778101579RHSA-2026:149372026-05-07T00:00:00Z
Red Hat Hardened Imagesopenssl-main-3.5.6-0.3.hum1RHSA-2026:142172026-05-06T00:00:00Z
Red Hat Hardened Imagesopenssl-main-3.5.6-0.1.hum1RHSA-2026:72612026-04-09T00:00:00Z

Package state

ProductPackageState
Confidential Cluster Operatorconfidential-clusters-beta/confidential-cluster-operator-bundleAffected
Confidential Cluster Operatorredhat-user-workloads/attestation-key-registerAffected
Confidential Cluster Operatorredhat-user-workloads/buildrootAffected
Confidential Cluster Operatorredhat-user-workloads/compute-pcrsAffected
Confidential Cluster Operatorredhat-user-workloads/confidential-cluster-operatorAffected
Confidential Cluster Operatorredhat-user-workloads/registration-serverAffected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleAffected
Confidential Compute Attestationredhat-user-workloads/osc-monitorAffected
Confidential Compute Attestationredhat-user-workloads/osc-monitor-v1-10Not affected
Confidential Compute Attestationredhat-user-workloads/osc-operatorAffected
Confidential Compute Attestationredhat-user-workloads/osc-operator-bundle-v1-10Not affected
Confidential Compute Attestationredhat-user-workloads/osc-operator-v1-10Not affected
Confidential Compute Attestationredhat-user-workloads/osc-podvm-builderAffected
Confidential Compute Attestationredhat-user-workloads/osc-podvm-builder-v1-10Not affected
Confidential Compute Attestationredhat-user-workloads/osc-podvm-payloadAffected
Confidential Compute Attestationredhat-user-workloads/osc-podvm-payload-v1-10Not affected
Confidential Compute Attestationredhat-user-workloads/trusteeAffected
Lightspeed Corelightspeed-core/dataverse-exporter-rhel9Affected
Logging Subsystem for Red Hat OpenShiftredhat-user-workloads/art-imagesNot affected
Logging Subsystem for Red Hat OpenShiftredhat-user-workloads/logging-vector-v6-2Affected
Logging Subsystem for Red Hat OpenShiftredhat-user-workloads/logging-vector-v6-4Affected
Migration Toolkit for Applications 8redhat-user-workloads/art-imagesAffected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-ragAffected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-to-dataverse-exporterAffected
OpenShift Service Mesh 3redhat-user-workloads/ossm-3-3-ztunnelNot affected
Pen Drive Powered by Red Hat Lightspeedredhat-user-workloads/pen-drive-scannerAffected
Red Hat 3scale API Management Platform 23scale-amp21/backendWill not fix
Red Hat 3scale API Management Platform 23scale-amp22/backendWill not fix
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Will not fix
Red Hat Advanced Cluster Security 4rhacs-eng/release-factAffected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/automation-reportsAffected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-supported-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-supported-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/de-minimal-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/ee-minimal-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/ee-supported-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/mcp-tools-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/metrics-service-rhel9Affected
Red Hat Ansible Automation Platform Ansible Core 2redhat-user-workloads/ee-minimal-ansible-core-2-18-rhel-8Affected
Red Hat Ansible Automation Platform Ansible Core 2redhat-user-workloads/ee-minimal-ansible-core-2-18-rhel-9Affected
Red Hat Ansible Automation Platform Ansible Core 2redhat-user-workloads/ee-minimal-ansible-core-2-19-rhel-8-tech-previewAffected
Red Hat Ansible Automation Platform Ansible Core 2redhat-user-workloads/ee-minimal-ansible-core-2-19-rhel-9-tech-previewAffected
Red Hat Ansible Automation Platform Ansible Core 2redhat-user-workloads/ee-minimal-ansible-core-2-20-rhel-8-tech-previewAffected
Red Hat Ansible Automation Platform Ansible Core 2redhat-user-workloads/ee-minimal-ansible-core-2-20-rhel-9-tech-previewAffected
Red Hat Connectivity Link 1redhat-user-workloads/rhcl-1-3-limitadorAffected
Red Hat Directory Server 11redhat-ds:11/389-ds-baseNot affected
Red Hat Directory Server 12redhat-ds:12/389-ds-baseNot affected
Red Hat Directory Server 13389-ds-baseNot affected
Red Hat Enterprise Linux 10389-ds-baseNot affected

Apply commands

bash fix
Apply RHSA-2026:14937 for Red Hat Discovery 2
yum update -y discovery/discovery-server-rhel9:1778101579
# or:
dnf upgrade -y discovery/discovery-server-rhel9:1778101579

Affected

VendorProductVersion
redhatConfidential Cluster OperatorAffected
redhatConfidential Cluster OperatorAffected
redhatConfidential Cluster OperatorAffected
redhatConfidential Cluster OperatorAffected
redhatConfidential Cluster OperatorAffected
redhatConfidential Cluster OperatorAffected
redhatConfidential Compute AttestationAffected
redhatConfidential Compute AttestationAffected
redhatConfidential Compute AttestationNot affected
redhatConfidential Compute AttestationAffected
redhatConfidential Compute AttestationNot affected
redhatConfidential Compute AttestationNot affected
redhatConfidential Compute AttestationAffected
redhatConfidential Compute AttestationNot affected
redhatConfidential Compute AttestationAffected
redhatConfidential Compute AttestationNot affected
redhatConfidential Compute AttestationAffected
redhatLightspeed CoreAffected
redhatLogging Subsystem for Red Hat OpenShiftNot affected
redhatLogging Subsystem for Red Hat OpenShiftAffected
redhatLogging Subsystem for Red Hat OpenShiftAffected
redhatMigration Toolkit for Applications 8Affected
redhatOpenShift LightspeedAffected
redhatOpenShift LightspeedAffected
redhatOpenShift Service Mesh 3Not affected
redhatPen Drive Powered by Red Hat LightspeedAffected
redhatRed Hat Advanced Cluster Security 4Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 3.5.5-1~deb13u2
sid Fixed 3.6.2-1
forky Fixed 3.6.2-1
bullseye Affected β€”
bookworm Fixed 3.0.19-1~deb12u2
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed openssl-devel-3.5.5-3.el9_8.i686.rpm
8 Fixed compat-openssl10-1.0.2o-4.el8_10.2.i686.rpm
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

Application impact

VendorProductVersionsFixed
openssl opensslopenssl{"startIncluding":"1.0.2","endExcluding":"1.0.2zp"}1.0.2zp
gcp googlegcp

References

CWEs

CWE-476

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.