The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-libsUpgrade openssl-develUpgrade compat-openssl10Upgrade opensslUpgrade openssl-perl | May 4, 2022 | Mar 15, 2022 |
| Alpine Linux | — | Upgrade libresslUpgrade openssl3Upgrade libretlsUpgrade opensslUpgrade lighthouseUpgrade openssl1.1-compatUpgrade openjdk11 | Mar 26, 2024 | Mar 15, 2022 |
| Amazon Linux Ami 2 | — | Upgrade mariadb-errmsgUpgrade openssl-libsUpgrade openssl11-staticUpgrade mariadb-libsUpgrade mariadb-testUpgrade openssl-perlUpgrade openssl11Upgrade openssl11-libsUpgrade mariadb-commonUpgrade mariadb-s3-engineUpgrade mariadb-server-galeraUpgrade mariadb-oqgraph-engineUpgrade edk2-debuginfoUpgrade aws-nitro-enclaves-acmUpgrade mariadb-serverUpgrade mariadb-backupUpgrade edk2-ovmfUpgrade edk2-toolsUpgrade mariadb-connect-engineUpgrade mariadb-sphinx-engineUpgrade openssl11-develUpgrade openssl-staticUpgrade edk2-tools-pythonUpgrade mariadb-embeddedUpgrade mariadb-cracklib-password-checkUpgrade mariadb-gssapi-serverUpgrade aws-nitro-enclaves-acm-debuginfoUpgrade mariadb-configUpgrade mariadb-pamUpgrade mariadbUpgrade openssl-debuginfoUpgrade mariadb-rocksdb-engineUpgrade mariadb-server-utilsUpgrade mariadb-debuginfoUpgrade edk2-aarch64Upgrade openssl-develUpgrade edk2-tools-docUpgrade mariadb-develUpgrade openssl11-debuginfoUpgrade mariadb-embedded-develUpgrade openssl | Jul 4, 2022 | Mar 15, 2022 |
| Amazon_linux | — | Upgrade openssl | Mar 17, 2022 | Mar 15, 2022 |
| Amazon_linux_2023 | — | Upgrade mariadb105-server-utilsUpgrade mariadb105-oqgraph-engineUpgrade mariadb105-sphinx-engine-debuginfoUpgrade mariadb105-debuginfoUpgrade mariadb105-oqgraph-engine-debuginfoUpgrade openssl-libsUpgrade mariadb105-commonUpgrade openssl-perlUpgrade mariadb105-serverUpgrade mariadb105Upgrade openssl-develUpgrade mariadb105-pamUpgrade mariadb105-rocksdb-engine-debuginfoUpgrade mariadb105-connect-engineUpgrade mariadb105-backup-debuginfoUpgrade mariadb105-rocksdb-engineUpgrade mariadb105-gssapi-server-debuginfoUpgrade mariadb105-sphinx-engineUpgrade mariadb105-cracklib-password-checkUpgrade mariadb105-connect-engine-debuginfoUpgrade openssl-libs-debuginfoUpgrade mariadb105-errmsgUpgrade mariadb105-debugsourceUpgrade openssl-debugsourceUpgrade mariadb105-develUpgrade mariadb105-gssapi-serverUpgrade mariadb105-testUpgrade mariadb105-pam-debuginfoUpgrade mariadb105-server-utils-debuginfoUpgrade mariadb105-backupUpgrade mariadb105-test-debuginfoUpgrade mariadb105-cracklib-password-check-debuginfoUpgrade opensslUpgrade mariadb105-server-debuginfoUpgrade openssl-debuginfo | Feb 17, 2025 | Mar 15, 2022 |
| Apple Osx Amd | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Apache | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appkit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appleavd | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appleevents | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applegraphicscontrol | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applemobilefileintegrity | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applescript | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Avevideoencoder | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Bluetooth | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Contacts | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Coretypes | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Cvms | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Driverkit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Facetime | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Graphicsdrivers | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Imageio | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Intelgraphicsdriver | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Iokit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Iomobileframebuffer | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Kernel | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Launchservices | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libinfo | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libresolv | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libressl | — | Apply OS X security update 2022-004 CatalinaUpgrade macOS to the latest version | May 17, 2022 | Mar 15, 2022 |
| Apple Osx Libxml2 | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Loginwindow | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Openssl | — | Apply OS X security update 2022-004 CatalinaUpgrade macOS to the latest version | May 17, 2022 | Mar 15, 2022 |
| Arista Eos | — | Upgrade to a remediated software version | Sep 4, 2024 | Apr 26, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 4, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 4, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 4, 2022 |
| Aruba Ecos | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Mar 17, 2025 | May 4, 2022 |
| Autodesk Autocad | — | Update Autodesk AutoCAD to the latest version for Windows and macOS. | Jul 22, 2025 | Jul 28, 2022 |
| Centos_linux | — | Upgrade compat-openssl11-debuginfoUpgrade openssl-libs-debuginfoUpgrade compat-openssl10-debugsourceUpgrade openssl-perlUpgrade opensslUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade compat-openssl11-debugsourceUpgrade compat-openssl11Upgrade compat-openssl10-debuginfoUpgrade openssl-staticUpgrade compat-openssl10 | Mar 29, 2022 | Mar 15, 2022 |
| Debian | — | Upgrade openssl | Mar 17, 2022 | Mar 15, 2022 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Sep 23, 2025 | Jun 15, 2022 |
| Dell Powerstore Dsa2024158 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2024 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 22, 2022 |
| Fortinet Forticlient | — | Update Fortinet FortiClient to the latest version | Jun 25, 2025 | Apr 1, 2022 |
| Fortinet Forticlientems | — | Upgrade Fortinet FortiClientEMS to the latest version | Nov 20, 2024 | Apr 1, 2022 |
| Freebsd | — | Upgrade mysql57-serverUpgrade mysql80-serverUpgrade openssl-develUpgrade FreeBSDUpgrade mysql80-clientUpgrade libressl-develUpgrade libresslUpgrade openssl-quictlsUpgrade openssl | Nov 4, 2022 | Apr 16, 2022 |
| Gentoo Linux | — | Upgrade net-libs/nodejs.Upgrade dev-libs/openssl. | Oct 17, 2022 | Mar 15, 2022 |
| Hp Ilo | — | Upgrade HP iLO 4 to version 2.81Upgrade HP iLO 5 to version 2.72 | Jun 4, 2024 | Mar 15, 2022 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 17, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade shim | Jun 7, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssl098e | May 25, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-staticUpgrade openssl111d-libsUpgrade openssl111dUpgrade openssl111d-devel | Apr 26, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-develUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl | Apr 26, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade shim | Jun 16, 2022 | Mar 15, 2022 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory35 | Oct 12, 2022 | Mar 15, 2022 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle Mysql | — | Upgrade to MySQL version 8.0.30Upgrade to MySQL version 5.7.38 | Jun 15, 2026 | Mar 15, 2022 |
| Oracle_linux | — | Upgrade compat-openssl10Upgrade openssl-staticUpgrade openssl-debugsourceUpgrade opensslUpgrade compat-openssl11Upgrade openssl-perlUpgrade openssl-libsUpgrade openssl-devel | Mar 19, 2022 | Mar 15, 2022 |
| Palo Alto Networks Globalprotect App | — | Update Palo Alto Networks GlobalProtect App to the latest version | May 21, 2025 | Mar 31, 2022 |
| Palo Alto Networks Pan Os | — | Upgrade Palo Alto Networks PAN-OS to the latest version | Jan 7, 2025 | Mar 31, 2022 |
| Panos | — | — | Apr 1, 2022 | Mar 15, 2022 |
| Pulse Secure Pulse Connect Secure | — | Update Ivanti Connect Secure to version 9.1R14.1Update Ivanti Connect Secure to version 22.1R1.0 | May 22, 2024 | Feb 14, 2023 |
| Redhat_linux | — | Upgrade openssl-debugsourceUpgrade compat-openssl11Upgrade compat-openssl10-debugsourceUpgrade opensslUpgrade openssl-develUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade compat-openssl10Upgrade compat-openssl10-debuginfoUpgrade compat-openssl11-debugsourceUpgrade compat-openssl11-debuginfoUpgrade openssl-static | Mar 29, 2022 | Mar 15, 2022 |
| Rocky_linux | — | Upgrade opensslUpgrade openssl-libs-debuginfoUpgrade compat-openssl11-debuginfoUpgrade compat-openssl10-debugsourceUpgrade openssl-debuginfoUpgrade compat-openssl11Upgrade compat-openssl10-debuginfoUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade compat-openssl10Upgrade compat-openssl11-debugsource | May 5, 2022 | Mar 15, 2022 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.17 or later | Sep 22, 2025 | Mar 22, 2022 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Mar 22, 2022 |
| Sonicwall Gms | — | Update SonicWall GMS to version 9.3.2 or later | Sep 4, 2025 | Mar 22, 2022 |
| Sonicwall Sma 100 | — | Upgrade SonicWall SMA-100 to the latest version | Jun 12, 2026 | Mar 22, 2022 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen7 to version 7.0.1-5052 or laterUpdate SonicWall SonicOS Gen6 to version 6.5.4.10-95n or later | May 25, 2026 | Mar 22, 2022 |
| Suse | — | Upgrade libopenssl-develUpgrade libopenssl3Upgrade openssl1Upgrade libopenssl0_9_8Upgrade libopenssl-1_1-develUpgrade openssl-1_1-docUpgrade libopenssl1_0_0Upgrade libopenssl0_9_8-hmacUpgrade libopenssl0_9_8-32bitUpgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl10Upgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl1_1-32bitUpgrade libopenssl-1_0_0-develUpgrade openssl-1_0_0-cavsUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_0_0-hmacUpgrade libopenssl1_1-hmacUpgrade openssl1-docUpgrade opensslUpgrade libopenssl1_0_0-steam-32bitUpgrade libopenssl1_0_0-x86Upgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade openssl-1_1Upgrade openssl-docUpgrade openssl-3Upgrade libopenssl1_1Upgrade openssl-1_0_0Upgrade libopenssl1-develUpgrade libopenssl1_0_0-steamUpgrade libopenssl-3-develUpgrade openssl-1_0_0-doc | Mar 16, 2022 | Mar 15, 2022 |
| Ubuntu | — | Upgrade ovmfUpgrade libssl1.0.0Upgrade libnode72Upgrade libnode-devUpgrade ovmf-ia32Upgrade qemu-efi-loongarch64Upgrade qemu-efi-aarch64Upgrade libssl1.1Upgrade qemu-efi-armUpgrade qemu-efi-riscv64Upgrade qemu-efiUpgrade nodejs-docUpgrade libssl1.0.0 (Ubuntu Pro)Upgrade nodejs | Mar 16, 2022 | Mar 15, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub