stable

openssl3-3.5.1-6.1.el8

FEDORA-EPEL-2025-8e15323af1 created by salimma a week ago for Fedora EPEL 8

Rebase to latest c9s openssl

Security Fix(es):

  • openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230)

This update has been submitted for testing by salimma.

a week ago

This update's test gating status has been changed to 'ignored'.

a week ago

This update has been pushed to testing.

a week ago

This update has been submitted for stable by bodhi.

2 days ago

This update has been pushed to stable.

a day ago
User Icon hurricos commented & provided feedback 9 hours ago
karma

As with FEDORA-EPEL-2024-2139fb0f65, it looks like gating was messed up on this compilation again, as the new build requires fips-provider-so usually supplied by openssl-provider-fips which isn't available through most EL8 derivatives, nor EPEL8.

I get basically the same error as https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-b002585dd2#comment-3511260:

[root@makowiec ~]# rpm -q --requires openssl3-libs # 3.2.2
ca-certificates >= 2008-5
crypto-policies >= 20180730
libc.so.6()(64bit)
:
libc.so.6(GLIBC_2.4)(64bit)
libcrypto.so.3()(64bit)
:
libcrypto.so.3(OPENSSL_3.2.0)(64bit)
libdl.so.2()(64bit)
libdl.so.2(GLIBC_2.2.5)(64bit)
:
libpthread.so.0(GLIBC_2.3.2)(64bit)
libz.so.1()(64bit)
rpmlib(CompressedFileNames) <= 3.0.4-1
rpmlib(FileDigests) <= 4.6.0-1
rpmlib(PayloadFilesHavePrefix) <= 4.0-1
rpmlib(PayloadIsXz) <= 5.2-1
rtld(GNU_HASH)
[root@makowiec ~]# dnf --enablerepo=epel repoquery --requires openssl3-libs # current requirements from upstream, 3.5.1
:
ca-certificates >= 2008-5
crypto-policies >= 20180730
fips-provider-so
libc.so.6(GLIBC_2.25)(64bit)
libdl.so.2()(64bit)
libdl.so.2(GLIBC_2.2.5)(64bit)
libpthread.so.0()(64bit)
libpthread.so.0(GLIBC_2.2.5)(64bit)
libpthread.so.0(GLIBC_2.3.2)(64bit)
libz.so.1()(64bit)
rtld(GNU_HASH)

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
-1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
2
Stable by Time
7 days
Dates
submitted
a week ago
in testing
a week ago
in stable
a day ago
approved
2 days ago
BZ#2400659 CVE-2025-9230 openssl3: Out-of-bounds read & write in RFC 3211 KEK Unwrap [epel-8]
0
0

Automated Test Results