The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade compat-openssl10Upgrade opensslUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl-devel | May 4, 2022 | Mar 15, 2022 |
| Alpine Linux | — | Upgrade libresslUpgrade libretlsUpgrade openssl3Upgrade opensslUpgrade openjdk11Upgrade lighthouseUpgrade openssl1.1-compat | Mar 26, 2024 | Mar 15, 2022 |
| Amazon Linux Ami 2 | — | Upgrade mariadb-rocksdb-engineUpgrade mariadb-gssapi-serverUpgrade edk2-aarch64Upgrade mariadb-debuginfoUpgrade mariadb-develUpgrade mariadb-pamUpgrade openssl-debuginfoUpgrade mariadb-configUpgrade mariadb-sphinx-engineUpgrade mariadb-cracklib-password-checkUpgrade edk2-tools-pythonUpgrade opensslUpgrade mariadb-embeddedUpgrade mariadb-server-utilsUpgrade mariadbUpgrade edk2-tools-docUpgrade openssl-develUpgrade mariadb-embedded-develUpgrade openssl-staticUpgrade aws-nitro-enclaves-acm-debuginfoUpgrade openssl11-develUpgrade openssl11-debuginfoUpgrade aws-nitro-enclaves-acmUpgrade mariadb-oqgraph-engineUpgrade mariadb-server-galeraUpgrade mariadb-testUpgrade openssl-perlUpgrade openssl11Upgrade edk2-toolsUpgrade mariadb-connect-engineUpgrade edk2-debuginfoUpgrade mariadb-backupUpgrade edk2-ovmfUpgrade openssl-libsUpgrade mariadb-libsUpgrade openssl11-libsUpgrade openssl11-staticUpgrade mariadb-s3-engineUpgrade mariadb-errmsgUpgrade mariadb-commonUpgrade mariadb-server | Jul 4, 2022 | Mar 15, 2022 |
| Amazon_linux | — | Upgrade openssl | Mar 17, 2022 | Mar 15, 2022 |
| Amazon_linux_2023 | — | Upgrade mariadb105-sphinx-engine-debuginfoUpgrade openssl-libsUpgrade mariadb105Upgrade openssl-perlUpgrade mariadb105-gssapi-server-debuginfoUpgrade mariadb105-commonUpgrade openssl-develUpgrade mariadb105-oqgraph-engineUpgrade mariadb105-pamUpgrade mariadb105-serverUpgrade mariadb105-oqgraph-engine-debuginfoUpgrade mariadb105-cracklib-password-checkUpgrade mariadb105-server-utilsUpgrade mariadb105-backup-debuginfoUpgrade mariadb105-debuginfoUpgrade mariadb105-rocksdb-engineUpgrade mariadb105-connect-engineUpgrade mariadb105-sphinx-engineUpgrade mariadb105-rocksdb-engine-debuginfoUpgrade mariadb105-server-debuginfoUpgrade mariadb105-connect-engine-debuginfoUpgrade mariadb105-pam-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade mariadb105-errmsgUpgrade mariadb105-debugsourceUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade mariadb105-cracklib-password-check-debuginfoUpgrade mariadb105-develUpgrade mariadb105-backupUpgrade mariadb105-test-debuginfoUpgrade mariadb105-testUpgrade mariadb105-gssapi-serverUpgrade mariadb105-server-utils-debuginfo | Feb 17, 2025 | Mar 15, 2022 |
| Apple Osx Amd | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Apache | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appkit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appleavd | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Appleevents | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applegraphicscontrol | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applemobilefileintegrity | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Applescript | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Avevideoencoder | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Bluetooth | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Contacts | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Coretypes | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Cvms | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Driverkit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Facetime | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Graphicsdrivers | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Imageio | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Intelgraphicsdriver | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Iokit | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Iomobileframebuffer | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Kernel | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Launchservices | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libinfo | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libresolv | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Libressl | — | Upgrade macOS to the latest versionApply OS X security update 2022-004 Catalina | May 17, 2022 | Mar 15, 2022 |
| Apple Osx Libxml2 | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Loginwindow | — | — | Oct 14, 2024 | Mar 15, 2022 |
| Apple Osx Openssl | — | Apply OS X security update 2022-004 CatalinaUpgrade macOS to the latest version | May 17, 2022 | Mar 15, 2022 |
| Arista Eos | — | Upgrade to a remediated software version | Sep 4, 2024 | Apr 26, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 4, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 4, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 4, 2022 |
| Aruba Ecos | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Mar 17, 2025 | May 4, 2022 |
| Autodesk Autocad | — | Update Autodesk AutoCAD to the latest version for Windows and macOS. | Jul 22, 2025 | Jul 28, 2022 |
| Centos_linux | — | Upgrade compat-openssl11-debuginfoUpgrade openssl-libs-debuginfoUpgrade compat-openssl10-debugsourceUpgrade openssl-perlUpgrade opensslUpgrade compat-openssl10-debuginfoUpgrade compat-openssl10Upgrade openssl-debugsourceUpgrade compat-openssl11-debugsourceUpgrade openssl-debuginfoUpgrade openssl-develUpgrade openssl-libsUpgrade compat-openssl11Upgrade openssl-static | Mar 29, 2022 | Mar 15, 2022 |
| Debian | — | Upgrade openssl | Mar 17, 2022 | Mar 15, 2022 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Sep 23, 2025 | Jun 15, 2022 |
| Dell Powerstore Dsa2024158 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2024 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 22, 2022 |
| Fortinet Forticlient | — | Update Fortinet FortiClient to the latest version | Jun 25, 2025 | Apr 1, 2022 |
| Fortinet Forticlientems | — | Upgrade Fortinet FortiClientEMS to the latest version | Nov 20, 2024 | Apr 1, 2022 |
| Freebsd | — | Upgrade openssl-develUpgrade mysql57-serverUpgrade mysql80-serverUpgrade openssl-quictlsUpgrade mysql80-clientUpgrade libressl-develUpgrade libresslUpgrade FreeBSDUpgrade openssl | Nov 4, 2022 | Apr 16, 2022 |
| Gentoo Linux | — | Upgrade net-libs/nodejs.Upgrade dev-libs/openssl. | Oct 17, 2022 | Mar 15, 2022 |
| Hp Ilo | — | Upgrade HP iLO 4 to version 2.81Upgrade HP iLO 5 to version 2.72 | Jun 4, 2024 | Mar 15, 2022 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 17, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade shim | Jun 7, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssl098e | May 25, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-staticUpgrade openssl111dUpgrade openssl111d-libsUpgrade openssl111d-devel | Apr 26, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-libsUpgrade opensslUpgrade openssl-perlUpgrade openssl-devel | Apr 26, 2022 | Mar 15, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade shim | Jun 16, 2022 | Mar 15, 2022 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory35 | Oct 12, 2022 | Mar 15, 2022 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle Mysql | — | Upgrade to MySQL version 5.7.38Upgrade to MySQL version 8.0.30 | Jun 15, 2026 | Mar 15, 2022 |
| Oracle_linux | — | Upgrade opensslUpgrade openssl-debugsourceUpgrade compat-openssl10Upgrade openssl-staticUpgrade compat-openssl11Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl-devel | Mar 19, 2022 | Mar 15, 2022 |
| Palo Alto Networks Globalprotect App | — | Update Palo Alto Networks GlobalProtect App to the latest version | May 21, 2025 | Mar 31, 2022 |
| Palo Alto Networks Pan Os | — | Upgrade Palo Alto Networks PAN-OS to the latest version | Jan 7, 2025 | Mar 31, 2022 |
| Panos | — | — | Apr 1, 2022 | Mar 15, 2022 |
| Pulse Secure Pulse Connect Secure | — | Update Ivanti Connect Secure to version 22.1R1.0Update Ivanti Connect Secure to version 9.1R14.1 | May 22, 2024 | Feb 14, 2023 |
| Redhat_linux | — | Upgrade openssl-staticUpgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade compat-openssl11-debuginfoUpgrade compat-openssl10-debuginfoUpgrade compat-openssl10Upgrade compat-openssl11-debugsourceUpgrade openssl-libsUpgrade openssl-debugsourceUpgrade opensslUpgrade openssl-debuginfoUpgrade compat-openssl10-debugsourceUpgrade compat-openssl11Upgrade openssl-devel | Mar 29, 2022 | Mar 15, 2022 |
| Rocky_linux | — | Upgrade openssl-debuginfoUpgrade compat-openssl11-debuginfoUpgrade openssl-libs-debuginfoUpgrade compat-openssl10-debugsourceUpgrade compat-openssl11Upgrade opensslUpgrade compat-openssl11-debugsourceUpgrade openssl-debugsourceUpgrade compat-openssl10-debuginfoUpgrade openssl-libsUpgrade compat-openssl10Upgrade openssl-perlUpgrade openssl-devel | May 5, 2022 | Mar 15, 2022 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.17 or later | Sep 22, 2025 | Mar 22, 2022 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Mar 22, 2022 |
| Sonicwall Gms | — | Update SonicWall GMS to version 9.3.2 or later | Sep 4, 2025 | Mar 22, 2022 |
| Sonicwall Sma 100 | — | Upgrade SonicWall SMA-100 to the latest version | Jun 12, 2026 | Mar 22, 2022 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen7 to version 7.0.1-5052 or laterUpdate SonicWall SonicOS Gen6 to version 6.5.4.10-95n or later | May 25, 2026 | Mar 22, 2022 |
| Suse | — | Upgrade opensslUpgrade openssl-3Upgrade openssl-1_0_0-docUpgrade libopenssl1_1-hmacUpgrade libopenssl1_0_0-steamUpgrade libopenssl1_0_0-steam-32bitUpgrade libopenssl1-develUpgrade openssl1-docUpgrade libopenssl1_1Upgrade libopenssl-3-develUpgrade libopenssl1_0_0-x86Upgrade openssl-1_0_0Upgrade libopenssl1_1-hmac-32bitUpgrade openssl-docUpgrade libopenssl0_9_8-hmac-32bitUpgrade openssl-1_1Upgrade libopenssl1_0_0-hmacUpgrade libopenssl0_9_8Upgrade libopenssl1_1-32bitUpgrade openssl1Upgrade libopenssl-1_1-develUpgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl-1_0_0-develUpgrade openssl-1_1-docUpgrade libopenssl0_9_8-hmacUpgrade libopenssl1_0_0Upgrade libopenssl-1_1-devel-32bitUpgrade openssl-1_0_0-cavsUpgrade libopenssl3Upgrade libopenssl0_9_8-32bitUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl-develUpgrade libopenssl10 | Mar 16, 2022 | Mar 15, 2022 |
| Ubuntu | — | Upgrade libnode72Upgrade qemu-efi-loongarch64Upgrade ovmfUpgrade qemu-efi-riscv64Upgrade libnode-devUpgrade qemu-efi-aarch64Upgrade ovmf-ia32Upgrade libssl1.0.0Upgrade qemu-efi-armUpgrade libssl1.1Upgrade nodejsUpgrade qemu-efiUpgrade libssl1.0.0 (Ubuntu Pro)Upgrade nodejs-doc | Mar 16, 2022 | Mar 15, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub