RHSA-2024:2447
Advisory lineage Upstream: 7 Downstream: 0
Published: 16 Sept 2024, 15:56
Last modified:03 Jun 2026, 10:07
Vulnerability Summary
Overall Risk (default)
medium
26/100 CVSS Score
6.5 MEDIUM
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
16 Sept 2024, 15:56
Published
Vulnerability first disclosed
03 Jun 2026, 10:07
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: openssl and openssl-fips-provider security update
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected Systems
- redhat•openssl
< 1:3.0.7-27.el9 | < 1:3.0.7-27.el9
- redhat•openssl-debuginfo
< 1:3.0.7-27.el9 | < 1:3.0.7-27.el9
- redhat•openssl-debugsource
< 1:3.0.7-27.el9 | < 1:3.0.7-27.el9
- redhat•openssl-devel
< 1:3.0.7-27.el9 | < 1:3.0.7-27.el9
- redhat•openssl-libs
< 1:3.0.7-27.el9 | < 1:3.0.7-27.el9
- redhat•openssl-libs-debuginfo
< 1:3.0.7-27.el9 | < 1:3.0.7-27.el9
- redhat•openssl-perl
< 1:3.0.7-27.el9 | < 1:3.0.7-27.el9
References (54)
- https://access.redhat.com/errata/RHSA-2024:2447
- https://access.redhat.com/security/updates/classification/#low
- https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.4_release_notes/index
- https://bugzilla.redhat.com/show_bug.cgi?id=2223016
- https://bugzilla.redhat.com/show_bug.cgi?id=2224962
- https://bugzilla.redhat.com/show_bug.cgi?id=2227852
- https://bugzilla.redhat.com/show_bug.cgi?id=2248616
- https://bugzilla.redhat.com/show_bug.cgi?id=2257571
- https://bugzilla.redhat.com/show_bug.cgi?id=2258502
- https://bugzilla.redhat.com/show_bug.cgi?id=2259944
- https://issues.redhat.com/browse/RHEL-14083
- https://issues.redhat.com/browse/RHEL-15990
- https://issues.redhat.com/browse/RHEL-17104
- https://issues.redhat.com/browse/RHEL-17193
- https://issues.redhat.com/browse/RHEL-1780
- https://issues.redhat.com/browse/RHEL-20249
- https://issues.redhat.com/browse/RHEL-5295
- https://issues.redhat.com/browse/RHEL-5304
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2447.json
- https://access.redhat.com/security/cve/CVE-2023-2975
- https://www.cve.org/CVERecord?id=CVE-2023-2975
- https://nvd.nist.gov/vuln/detail/CVE-2023-2975
- https://www.openssl.org/news/secadv/20230714.txt
- https://access.redhat.com/security/cve/CVE-2023-3446
- https://www.cve.org/CVERecord?id=CVE-2023-3446
- https://nvd.nist.gov/vuln/detail/CVE-2023-3446
- https://www.openssl.org/news/secadv/20230719.txt
- https://access.redhat.com/security/cve/CVE-2023-3817
- https://www.cve.org/CVERecord?id=CVE-2023-3817
- https://nvd.nist.gov/vuln/detail/CVE-2023-3817
- https://www.openssl.org/news/secadv/20230731.txt
- https://access.redhat.com/security/cve/CVE-2023-5678
- https://www.cve.org/CVERecord?id=CVE-2023-5678
- https://nvd.nist.gov/vuln/detail/CVE-2023-5678
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6
- https://www.openssl.org/news/secadv/20231106.txt
- https://access.redhat.com/security/cve/CVE-2023-6129
- https://www.cve.org/CVERecord?id=CVE-2023-6129
- https://nvd.nist.gov/vuln/detail/CVE-2023-6129
- https://www.openssl.org/news/secadv/20240109.txt
- https://www.openwall.com/lists/oss-security/2024/01/09/1
- https://access.redhat.com/security/cve/CVE-2023-6237
- https://www.cve.org/CVERecord?id=CVE-2023-6237
- https://nvd.nist.gov/vuln/detail/CVE-2023-6237
- https://www.openssl.org/news/secadv/20240115.txt
- https://www.openwall.com/lists/oss-security/2024/01/15/2
- https://access.redhat.com/security/cve/CVE-2024-0727
- https://www.cve.org/CVERecord?id=CVE-2024-0727
- https://nvd.nist.gov/vuln/detail/CVE-2024-0727
- https://github.com/openssl/openssl/pull/23362
- https://www.openssl.org/news/secadv/20240125.txt