The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensslUpgrade compat-openssl10Upgrade openssl-perlUpgrade openssl-develUpgrade openssl-libs | May 4, 2022 | Mar 15, 2022 |
| Alpine Linux | — | Upgrade openssl1.1-compatUpgrade openjdk11Upgrade lighthouseUpgrade opensslUpgrade libresslUpgrade openssl3Upgrade libretls | Mar 26, 2024 | Mar 15, 2022 |
| Amazon Linux Ami 2 | — | Upgrade aws-nitro-enclaves-acm-debuginfoUpgrade opensslUpgrade edk2-tools-pythonUpgrade mariadb-rocksdb-engineUpgrade openssl-staticUpgrade mariadb-develUpgrade openssl-debuginfoUpgrade edk2-tools-docUpgrade openssl-develUpgrade mariadb-configUpgrade mariadb-cracklib-password-checkUpgrade mariadb-gssapi-serverUpgrade mariadb-pamUpgrade mariadb-embeddedUpgrade mariadb-sphinx-engineUpgrade mariadbUpgrade mariadb-server-utilsUpgrade mariadb-debuginfoUpgrade edk2-aarch64Upgrade mariadb-embedded-develUpgrade openssl11-debuginfoUpgrade openssl11-develUpgrade mariadb-commonUpgrade mariadb-errmsgUpgrade edk2-toolsUpgrade openssl11-libsUpgrade mariadb-s3-engineUpgrade mariadb-connect-engineUpgrade edk2-ovmfUpgrade mariadb-backupUpgrade openssl-libsUpgrade mariadb-libsUpgrade openssl11-staticUpgrade mariadb-oqgraph-engineUpgrade openssl11Upgrade edk2-debuginfoUpgrade mariadb-serverUpgrade aws-nitro-enclaves-acmUpgrade openssl-perlUpgrade mariadb-testUpgrade mariadb-server-galera | Jul 4, 2022 | Mar 15, 2022 |
| Amazon_linux | — | Upgrade openssl | Mar 17, 2022 | Mar 15, 2022 |
| Amazon_linux_2023 | — | Upgrade openssl-perlUpgrade mariadb105-oqgraph-engineUpgrade mariadb105Upgrade openssl-libsUpgrade openssl-develUpgrade mariadb105-server-utilsUpgrade mariadb105-commonUpgrade mariadb105-sphinx-engine-debuginfoUpgrade mariadb105-oqgraph-engine-debuginfoUpgrade mariadb105-backup-debuginfoUpgrade mariadb105-connect-engineUpgrade mariadb105-sphinx-engineUpgrade mariadb105-serverUpgrade mariadb105-gssapi-server-debuginfoUpgrade mariadb105-debuginfoUpgrade mariadb105-rocksdb-engine-debuginfoUpgrade mariadb105-pamUpgrade mariadb105-cracklib-password-checkUpgrade mariadb105-rocksdb-engineUpgrade mariadb105-debugsourceUpgrade mariadb105-server-utils-debuginfoUpgrade mariadb105-backupUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade mariadb105-develUpgrade mariadb105-server-debuginfoUpgrade mariadb105-cracklib-password-check-debuginfoUpgrade mariadb105-connect-engine-debuginfoUpgrade mariadb105-gssapi-serverUpgrade mariadb105-test-debuginfoUpgrade mariadb105-testUpgrade opensslUpgrade openssl-debugsourceUpgrade mariadb105-errmsgUpgrade mariadb105-pam-debuginfo | Feb 17, 2025 | Mar 15, 2022 |
| Apple Osx Amd | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Apache | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appkit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appleavd | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appleevents | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applegraphicscontrol | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applemobilefileintegrity | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applescript | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Avevideoencoder | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Bluetooth | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Contacts | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Coretypes | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Cvms | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Driverkit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Facetime | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Graphicsdrivers | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Imageio | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Intelgraphicsdriver | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Iokit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Iomobileframebuffer | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Kernel | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Launchservices | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libinfo | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libresolv | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libressl | — | Apply OS X security update 2022-004 CatalinaUpgrade macOS to the latest version | May 17, 2022 | Mar 15, 2022 |
| Apple Osx Libxml2 | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Loginwindow | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Openssl | — | Apply OS X security update 2022-004 CatalinaUpgrade macOS to the latest version | May 17, 2022 | Mar 15, 2022 |
| Arista Eos | — | Upgrade to a remediated software version | Sep 4, 2024 | Apr 26, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 4, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 4, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 4, 2022 |
| Aruba Ecos | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Mar 17, 2025 | May 4, 2022 |
| Autodesk Autocad | — | Update Autodesk AutoCAD to the latest version for Windows and macOS. | Jul 22, 2025 | Jul 28, 2022 |
| Centos_linux | — | Upgrade openssl-libsUpgrade openssl-debugsourceUpgrade openssl-staticUpgrade openssl-develUpgrade openssl-debuginfoUpgrade compat-openssl11Upgrade compat-openssl11-debugsourceUpgrade compat-openssl10Upgrade compat-openssl10-debuginfoUpgrade openssl-libs-debuginfoUpgrade compat-openssl10-debugsourceUpgrade opensslUpgrade openssl-perlUpgrade compat-openssl11-debuginfo | Mar 29, 2022 | Mar 15, 2022 |
| Debian | — | Upgrade openssl | Mar 17, 2022 | Mar 15, 2022 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Sep 23, 2025 | Jun 15, 2022 |
| Dell Powerstore Dsa2024158 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2024 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 22, 2022 |
| Fortinet Forticlient | — | Update Fortinet FortiClient to the latest version | Jun 25, 2025 | Apr 1, 2022 |
| Fortinet Forticlientems | — | Upgrade Fortinet FortiClientEMS to the latest version | Nov 20, 2024 | Apr 1, 2022 |
| Freebsd | — | Upgrade FreeBSDUpgrade libresslUpgrade mysql80-clientUpgrade libressl-develUpgrade opensslUpgrade openssl-quictlsUpgrade openssl-develUpgrade mysql57-serverUpgrade mysql80-server | Nov 4, 2022 | Apr 16, 2022 |
| Gentoo Linux | — | Upgrade net-libs/nodejs.Upgrade dev-libs/openssl. | Oct 17, 2022 | Mar 15, 2022 |
| Hp Ilo | — | Upgrade HP iLO 5 to version 2.72Upgrade HP iLO 4 to version 2.81 | Jun 4, 2024 | Mar 15, 2022 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 17, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade shim | Jun 7, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssl098e | May 25, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-develUpgrade openssl111d-staticUpgrade openssl111d-libsUpgrade openssl111d | Apr 26, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade opensslUpgrade openssl-devel | Apr 26, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade shim | Jun 16, 2022 | Mar 15, 2022 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory35 | Oct 12, 2022 | Mar 15, 2022 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle Mysql | — | Upgrade to MySQL version 5.7.38Upgrade to MySQL version 8.0.30 | Jun 15, 2026 | Mar 15, 2022 |
| Oracle_linux | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl-develUpgrade compat-openssl11Upgrade compat-openssl10Upgrade openssl-staticUpgrade openssl-debugsourceUpgrade openssl | Mar 19, 2022 | Mar 15, 2022 |
| Palo Alto Networks Globalprotect App | — | Update Palo Alto Networks GlobalProtect App to the latest version | May 21, 2025 | Mar 31, 2022 |
| Palo Alto Networks Pan Os | — | Upgrade Palo Alto Networks PAN-OS to the latest version | Jan 7, 2025 | Mar 31, 2022 |
| Panos | — | — | Apr 1, 2022 | Mar 15, 2022 |
| Pulse Secure Pulse Connect Secure | — | Update Ivanti Connect Secure to version 9.1R14.1Update Ivanti Connect Secure to version 22.1R1.0 | May 22, 2024 | Feb 14, 2023 |
| Redhat_linux | — | Upgrade compat-openssl11-debugsourceUpgrade compat-openssl10Upgrade compat-openssl11-debuginfoUpgrade openssl-staticUpgrade openssl-libs-debuginfoUpgrade openssl-perlUpgrade compat-openssl10-debuginfoUpgrade opensslUpgrade openssl-develUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade compat-openssl10-debugsourceUpgrade openssl-debugsourceUpgrade compat-openssl11 | Mar 29, 2022 | Mar 15, 2022 |
| Rocky_linux | — | Upgrade opensslUpgrade compat-openssl11Upgrade compat-openssl11-debuginfoUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfoUpgrade compat-openssl10-debugsourceUpgrade openssl-perlUpgrade compat-openssl10-debuginfoUpgrade openssl-develUpgrade openssl-debugsourceUpgrade compat-openssl10Upgrade compat-openssl11-debugsourceUpgrade openssl-libs | May 5, 2022 | Mar 15, 2022 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.17 or later | Sep 22, 2025 | Mar 22, 2022 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Mar 22, 2022 |
| Sonicwall Gms | — | Update SonicWall GMS to version 9.3.2 or later | Sep 4, 2025 | Mar 22, 2022 |
| Sonicwall Sma 100 | — | Upgrade SonicWall SMA-100 to the latest version | Jun 12, 2026 | Mar 22, 2022 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen7 to version 7.0.1-5052 or laterUpdate SonicWall SonicOS Gen6 to version 6.5.4.10-95n or later | May 25, 2026 | Mar 22, 2022 |
| Suse | — | Upgrade libopenssl1_1-32bitUpgrade libopenssl-1_0_0-develUpgrade openssl-1_1-docUpgrade libopenssl0_9_8-hmacUpgrade libopenssl10Upgrade libopenssl-develUpgrade libopenssl0_9_8-32bitUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl1_0_0-32bitUpgrade libopenssl3Upgrade openssl1Upgrade libopenssl-1_1-develUpgrade libopenssl0_9_8Upgrade libopenssl-1_1-devel-32bitUpgrade openssl-1_0_0-cavsUpgrade libopenssl1_0_0Upgrade opensslUpgrade openssl-docUpgrade openssl-1_0_0-docUpgrade openssl-3Upgrade libopenssl1_1-hmacUpgrade libopenssl1_1Upgrade libopenssl1_0_0-steam-32bitUpgrade libopenssl1-develUpgrade openssl-1_0_0Upgrade libopenssl1_0_0-x86Upgrade libopenssl-3-develUpgrade libopenssl1_0_0-steamUpgrade libopenssl1_0_0-hmacUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl0_9_8-hmac-32bitUpgrade openssl-1_1Upgrade openssl1-doc | Mar 16, 2022 | Mar 15, 2022 |
| Ubuntu | — | Upgrade qemu-efi-loongarch64Upgrade qemu-efi-armUpgrade ovmfUpgrade libssl1.0.0Upgrade libnode-devUpgrade libssl1.1Upgrade qemu-efi-aarch64Upgrade qemu-efi-riscv64Upgrade ovmf-ia32Upgrade libnode72Upgrade nodejsUpgrade nodejs-docUpgrade qemu-efiUpgrade libssl1.0.0 (Ubuntu Pro) | Mar 16, 2022 | Mar 15, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub