Security fix for CVE-2022-3602 and CVE-2022-3786
Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:
sudo dnf upgrade --refresh --advisory=FEDORA-2022-0f1d2e0537
Please login to add feedback.
This update has been submitted for testing by dbelyavs.
This update's test gating status has been changed to 'waiting'.
Tested on x86_64 and aarch64 across a number of services that use openssl inc openssh, postfix, dovecot, httpd using TLS1.2 and 1.3 and a number of client apps
If the build fixes CVE-2022-3786, then BZ#2139151 and BZ#2139104 should also be linked to this update?
As soon as the test gating status changes to "passed", another +1 (even from someone who already gave +1) will be necessary to get it submitted for stable.
adamwill edited this update.
Works fine within F37 x86_64 KVM VM. CVEs not verified/checked.
This update's test gating status has been changed to 'failed'.
LGTM
This update's test gating status has been changed to 'passed'.
This update has been submitted for stable by adamwill.
This update has been pushed to stable.
Hi @nb
how did you test for the CVEs? Thank you.