The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-develUpgrade openssl-libsUpgrade opensslUpgrade compat-openssl10Upgrade openssl-perl | May 4, 2022 | Mar 15, 2022 |
| Alpine Linux | — | Upgrade libresslUpgrade openssl3Upgrade opensslUpgrade libretlsUpgrade openjdk11Upgrade openssl1.1-compatUpgrade lighthouse | Mar 26, 2024 | Mar 15, 2022 |
| Amazon Linux Ami 2 | — | Upgrade mariadb-debuginfoUpgrade mariadbUpgrade mariadb-develUpgrade edk2-tools-docUpgrade mariadb-embedded-develUpgrade mariadb-pamUpgrade openssl11-debuginfoUpgrade openssl11-develUpgrade openssl-develUpgrade mariadb-sphinx-engineUpgrade aws-nitro-enclaves-acm-debuginfoUpgrade edk2-tools-pythonUpgrade edk2-aarch64Upgrade mariadb-rocksdb-engineUpgrade mariadb-server-utilsUpgrade opensslUpgrade mariadb-cracklib-password-checkUpgrade mariadb-embeddedUpgrade openssl-debuginfoUpgrade openssl-staticUpgrade mariadb-configUpgrade mariadb-gssapi-serverUpgrade edk2-ovmfUpgrade openssl-libsUpgrade mariadb-commonUpgrade openssl11-libsUpgrade mariadb-libsUpgrade mariadb-s3-engineUpgrade mariadb-errmsgUpgrade edk2-debuginfoUpgrade openssl11Upgrade mariadb-oqgraph-engineUpgrade openssl11-staticUpgrade mariadb-connect-engineUpgrade aws-nitro-enclaves-acmUpgrade edk2-toolsUpgrade mariadb-testUpgrade mariadb-backupUpgrade mariadb-serverUpgrade openssl-perlUpgrade mariadb-server-galera | Jul 4, 2022 | Mar 15, 2022 |
| Amazon_linux | — | Upgrade openssl | Mar 17, 2022 | Mar 15, 2022 |
| Amazon_linux_2023 | — | Upgrade mariadb105-gssapi-server-debuginfoUpgrade mariadb105-sphinx-engine-debuginfoUpgrade mariadb105-cracklib-password-checkUpgrade mariadb105-sphinx-engineUpgrade openssl-perlUpgrade mariadb105-commonUpgrade openssl-libsUpgrade mariadb105-oqgraph-engineUpgrade mariadb105-oqgraph-engine-debuginfoUpgrade openssl-develUpgrade mariadb105-backup-debuginfoUpgrade mariadb105-pamUpgrade mariadb105-server-utilsUpgrade mariadb105Upgrade mariadb105-debuginfoUpgrade mariadb105-rocksdb-engine-debuginfoUpgrade mariadb105-serverUpgrade mariadb105-connect-engineUpgrade mariadb105-rocksdb-engineUpgrade mariadb105-testUpgrade mariadb105-server-utils-debuginfoUpgrade mariadb105-backupUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade mariadb105-cracklib-password-check-debuginfoUpgrade mariadb105-server-debuginfoUpgrade mariadb105-connect-engine-debuginfoUpgrade mariadb105-develUpgrade mariadb105-errmsgUpgrade mariadb105-debugsourceUpgrade openssl-debugsourceUpgrade mariadb105-pam-debuginfoUpgrade mariadb105-test-debuginfoUpgrade mariadb105-gssapi-server | Feb 17, 2025 | Mar 15, 2022 |
| Apple Osx Amd | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Apache | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appkit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appleavd | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appleevents | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applegraphicscontrol | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applemobilefileintegrity | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applescript | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Avevideoencoder | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Bluetooth | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Contacts | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Coretypes | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Cvms | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Driverkit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Facetime | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Graphicsdrivers | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Imageio | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Intelgraphicsdriver | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Iokit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Iomobileframebuffer | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Kernel | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Launchservices | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libinfo | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libresolv | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libressl | — | Apply OS X security update 2022-004 CatalinaUpgrade macOS to the latest version | May 17, 2022 | Mar 15, 2022 |
| Apple Osx Libxml2 | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Loginwindow | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Openssl | — | Apply OS X security update 2022-004 CatalinaUpgrade macOS to the latest version | May 17, 2022 | Mar 15, 2022 |
| Arista Eos | — | Upgrade to a remediated software version | Sep 4, 2024 | Apr 26, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 4, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 4, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 4, 2022 |
| Aruba Ecos | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Mar 17, 2025 | May 4, 2022 |
| Autodesk Autocad | — | Update Autodesk AutoCAD to the latest version for Windows and macOS. | Jul 22, 2025 | Jul 28, 2022 |
| Centos_linux | — | Upgrade openssl-libsUpgrade compat-openssl11Upgrade openssl-debugsourceUpgrade compat-openssl10Upgrade compat-openssl10-debuginfoUpgrade openssl-debuginfoUpgrade openssl-staticUpgrade openssl-develUpgrade compat-openssl11-debugsourceUpgrade openssl-perlUpgrade compat-openssl11-debuginfoUpgrade openssl-libs-debuginfoUpgrade compat-openssl10-debugsourceUpgrade openssl | Mar 29, 2022 | Mar 15, 2022 |
| Debian | — | Upgrade openssl | Mar 17, 2022 | Mar 15, 2022 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Sep 23, 2025 | Jun 15, 2022 |
| Dell Powerstore Dsa2024158 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2024 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 22, 2022 |
| Fortinet Forticlient | — | Update Fortinet FortiClient to the latest version | Jun 25, 2025 | Apr 1, 2022 |
| Fortinet Forticlientems | — | Upgrade Fortinet FortiClientEMS to the latest version | Nov 20, 2024 | Apr 1, 2022 |
| Freebsd | — | Upgrade mysql80-clientUpgrade FreeBSDUpgrade libressl-develUpgrade openssl-quictlsUpgrade opensslUpgrade libresslUpgrade mysql80-serverUpgrade openssl-develUpgrade mysql57-server | Nov 4, 2022 | Apr 16, 2022 |
| Gentoo Linux | — | Upgrade dev-libs/openssl.Upgrade net-libs/nodejs. | Oct 17, 2022 | Mar 15, 2022 |
| Hp Ilo | — | Upgrade HP iLO 4 to version 2.81Upgrade HP iLO 5 to version 2.72 | Jun 4, 2024 | Mar 15, 2022 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 17, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade shim | Jun 7, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssl098e | May 25, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-develUpgrade openssl111dUpgrade openssl111d-staticUpgrade openssl111d-libs | Apr 26, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade opensslUpgrade openssl-devel | Apr 26, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade shim | Jun 16, 2022 | Mar 15, 2022 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory35 | Oct 12, 2022 | Mar 15, 2022 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle Mysql | — | Upgrade to MySQL version 8.0.30Upgrade to MySQL version 5.7.38 | Jun 15, 2026 | Mar 15, 2022 |
| Oracle_linux | — | Upgrade opensslUpgrade compat-openssl10Upgrade openssl-staticUpgrade openssl-debugsourceUpgrade openssl-perlUpgrade compat-openssl11Upgrade openssl-develUpgrade openssl-libs | Mar 19, 2022 | Mar 15, 2022 |
| Palo Alto Networks Globalprotect App | — | Update Palo Alto Networks GlobalProtect App to the latest version | May 21, 2025 | Mar 31, 2022 |
| Palo Alto Networks Pan Os | — | Upgrade Palo Alto Networks PAN-OS to the latest version | Jan 7, 2025 | Mar 31, 2022 |
| Panos | — | — | Apr 1, 2022 | Mar 15, 2022 |
| Pulse Secure Pulse Connect Secure | — | Update Ivanti Connect Secure to version 9.1R14.1Update Ivanti Connect Secure to version 22.1R1.0 | May 22, 2024 | Feb 14, 2023 |
| Redhat_linux | — | Upgrade opensslUpgrade compat-openssl11Upgrade openssl-debuginfoUpgrade openssl-develUpgrade compat-openssl10-debugsourceUpgrade openssl-libsUpgrade openssl-debugsourceUpgrade openssl-perlUpgrade compat-openssl11-debuginfoUpgrade openssl-libs-debuginfoUpgrade compat-openssl10Upgrade compat-openssl10-debuginfoUpgrade compat-openssl11-debugsourceUpgrade openssl-static | Mar 29, 2022 | Mar 15, 2022 |
| Rocky_linux | — | Upgrade openssl-libsUpgrade openssl-debugsourceUpgrade openssl-perlUpgrade openssl-develUpgrade compat-openssl10Upgrade compat-openssl10-debuginfoUpgrade compat-openssl11-debugsourceUpgrade compat-openssl11-debuginfoUpgrade compat-openssl11Upgrade opensslUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade compat-openssl10-debugsource | May 5, 2022 | Mar 15, 2022 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.17 or later | Sep 22, 2025 | Mar 22, 2022 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Mar 22, 2022 |
| Sonicwall Gms | — | Update SonicWall GMS to version 9.3.2 or later | Sep 4, 2025 | Mar 22, 2022 |
| Sonicwall Sma 100 | — | Upgrade SonicWall SMA-100 to the latest version | Jun 12, 2026 | Mar 22, 2022 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen6 to version 6.5.4.10-95n or laterUpdate SonicWall SonicOS Gen7 to version 7.0.1-5052 or later | May 25, 2026 | Mar 22, 2022 |
| Suse | — | Upgrade libopenssl-1_0_0-develUpgrade openssl-1_0_0-cavsUpgrade libopenssl1_1-32bitUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl0_9_8-hmacUpgrade libopenssl1_0_0-32bitUpgrade libopenssl-develUpgrade libopenssl10Upgrade libopenssl3Upgrade openssl1Upgrade openssl-1_1-docUpgrade libopenssl-1_1-develUpgrade libopenssl1_0_0Upgrade libopenssl0_9_8Upgrade libopenssl0_9_8-32bitUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl1_0_0-steam-32bitUpgrade libopenssl-3-develUpgrade libopenssl1_0_0-x86Upgrade openssl1-docUpgrade openssl-3Upgrade openssl-1_0_0-docUpgrade openssl-1_0_0Upgrade libopenssl1_1Upgrade libopenssl1_1-hmacUpgrade opensslUpgrade libopenssl1_0_0-hmacUpgrade libopenssl0_9_8-hmac-32bitUpgrade openssl-1_1Upgrade libopenssl1_0_0-steamUpgrade libopenssl1-develUpgrade openssl-docUpgrade libopenssl1_1-hmac-32bit | Mar 16, 2022 | Mar 15, 2022 |
| Ubuntu | — | Upgrade ovmfUpgrade qemu-efi-armUpgrade libnode72Upgrade ovmf-ia32Upgrade libssl1.1Upgrade libnode-devUpgrade qemu-efi-aarch64Upgrade qemu-efi-loongarch64Upgrade qemu-efi-riscv64Upgrade libssl1.0.0Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade nodejsUpgrade qemu-efiUpgrade nodejs-doc | Mar 16, 2022 | Mar 15, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub