- Issued:
- 2025-11-11
- Updated:
- 2025-11-11
RHBA-2025:20537 - Bug Fix Advisory
Synopsis
openssl and openssl-fips-provider bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for multiple packages is now available for Red Hat Enterprise Linux 9.
Description
For detailed information on changes in this release, see the Red Hat Enterprise Linux 9 Release Notes linked from the References section.
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
Affected Products
- Red Hat Enterprise Linux for x86_64 9 x86_64
- Red Hat Enterprise Linux for IBM z Systems 9 s390x
- Red Hat Enterprise Linux for Power, little endian 9 ppc64le
- Red Hat Enterprise Linux for ARM 64 9 aarch64
Fixes
- RHEL-85954 - openssl calls "close(-1)" if /dev/z90crypt is missing on s390x
- RHEL-88910 - OpenSSL ignores "rh-allow-sha1-signatures = yes" option on RHEL-9
- RHEL-88912 - pkcs12 should not default to pbmac1 in FIPS mode in RHEL-9
- RHEL-89859 - NO-ENFORCE-EMS no longer works after rebase to 3.5 [RHEL-9]
- RHEL-89860 - Openssl speed reports error in FIPS mode [RHEL-9]
- RHEL-89861 - pkeyutl ecdsa sha1 digest is allowed after rebase [RHEL-9]
- RHEL-89862 - Expose settable params [RHEL-9]
- RHEL-90854 - Enable sslkeylogfile support [RHEL-9]
- RHEL-95239 - Make hybrid MLKEM work with our FIPS provider (3.0.7) [Rhel 9.7]
- RHEL-97797 - Change config_diagnostics comment to make sense again [RHEL-9.7]
- RHEL-98723 - SSLKEYLOGFILE creates file with with lax permissions
- RHEL-105007 - fips-provider-next is installed by default
- RHEL-104856 - fips-provider-next is installed by default
CVEs
(none)
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 9
| SRPM | |
|---|---|
| openssl-3.5.1-3.el9.src.rpm | SHA-256: 68c2409b36474e010052c30e30c0b0607f12dea8042e08fa77835e5d5bdec761 |
| openssl-fips-provider-3.0.7-8.el9.src.rpm | SHA-256: f6e518e04053c5ff00bea751cd9bad3bd7a2be0eb8259b9d45b3cf1a80438bb9 |
| x86_64 | |
| openssl-3.5.1-3.el9.x86_64.rpm | SHA-256: f70d967a121988f3dc3477ac0eb708f212820e18dd202fc5fb32e9de109f3af7 |
| openssl-debuginfo-3.5.1-3.el9.i686.rpm | SHA-256: cd9732e6ef44b147501e1999e9f62ef6b1bb93aa08a11a0c6381542a93867b19 |
| openssl-debuginfo-3.5.1-3.el9.i686.rpm | SHA-256: cd9732e6ef44b147501e1999e9f62ef6b1bb93aa08a11a0c6381542a93867b19 |
| openssl-debuginfo-3.5.1-3.el9.x86_64.rpm | SHA-256: 064cef0d8dc712d796830f084ed261ec4050d0f3c0e18f3ff4eb2ef45d0c2dac |
| openssl-debuginfo-3.5.1-3.el9.x86_64.rpm | SHA-256: 064cef0d8dc712d796830f084ed261ec4050d0f3c0e18f3ff4eb2ef45d0c2dac |
| openssl-debugsource-3.5.1-3.el9.i686.rpm | SHA-256: 543fd453e728710efb1b45a8d9c1c96298f9734923e6310d2dcf5ba2d78f7039 |
| openssl-debugsource-3.5.1-3.el9.i686.rpm | SHA-256: 543fd453e728710efb1b45a8d9c1c96298f9734923e6310d2dcf5ba2d78f7039 |
| openssl-debugsource-3.5.1-3.el9.x86_64.rpm | SHA-256: 62ccebe6fb9b6b2a1f32a70d349e609ff9037a68d354ba904efb17959eb96e0a |
| openssl-debugsource-3.5.1-3.el9.x86_64.rpm | SHA-256: 62ccebe6fb9b6b2a1f32a70d349e609ff9037a68d354ba904efb17959eb96e0a |
| openssl-devel-3.5.1-3.el9.i686.rpm | SHA-256: 580ab07a23e92515324f23764e5c9ffc6c3c9d7cbb89259eff92dafd9d35fcf2 |
| openssl-devel-3.5.1-3.el9.x86_64.rpm | SHA-256: 5f6f01beb82b6ee4179be44de3a3821dd57c33b28b35385ffa844a96355fa8cf |
| openssl-fips-provider-3.0.7-8.el9.i686.rpm | SHA-256: f1f0ef70fe4e3352c1e1bbbcd4477c852237f10c9d9999115ed664081dbfc155 |
| openssl-fips-provider-3.0.7-8.el9.x86_64.rpm | SHA-256: bbf25303def8e1270675531c47bdad432f6ad8ef4c327556ae65bd6abaf8edb5 |
| openssl-fips-provider-so-3.0.7-8.el9.x86_64.rpm | SHA-256: ab48d98504fae6f8636de027a1ee06d21d5e9c27b7beb247017a6fe55567c5e9 |
| openssl-fips-provider-so-debuginfo-3.0.7-8.el9.i686.rpm | SHA-256: a4e883f91e77af66cbdd01729f19de2fff1c86dd9f754cc581fc353c2b08ca6b |
| openssl-fips-provider-so-debuginfo-3.0.7-8.el9.x86_64.rpm | SHA-256: 7473db92a9d2b7ed653cc150dc7bb86f56678e8363cd25e09f648de3ef21b64a |
| openssl-fips-provider-so-debugsource-3.0.7-8.el9.i686.rpm | SHA-256: e8cfcb00af19c4335330697a33a86f13dd881605b2f82376e22c28dbccc69fd9 |
| openssl-fips-provider-so-debugsource-3.0.7-8.el9.x86_64.rpm | SHA-256: 16705bf6eb812c8ce5fd24a289d045f2000fc691d70703485dcf5e95f001e6cc |
| openssl-libs-3.5.1-3.el9.i686.rpm | SHA-256: 706ed6bfc463fcaea6b84d0785674ba4fbcb60843aa72811d4790c73aedecc33 |
| openssl-libs-3.5.1-3.el9.x86_64.rpm | SHA-256: 57165c83b141af93bd0fdba087d7702acba3161867e5c3f0edcd5fabe405bffe |
| openssl-libs-debuginfo-3.5.1-3.el9.i686.rpm | SHA-256: f2134a83c406b93d2acc363e8ed54c289428a3d7ed2f28dc574d396b5023240b |
| openssl-libs-debuginfo-3.5.1-3.el9.i686.rpm | SHA-256: f2134a83c406b93d2acc363e8ed54c289428a3d7ed2f28dc574d396b5023240b |
| openssl-libs-debuginfo-3.5.1-3.el9.x86_64.rpm | SHA-256: 5d0fe289cd28f5d91c8b89ac6885bf36bd5240b0b4a3217a9fa27c6ca08f43cc |
| openssl-libs-debuginfo-3.5.1-3.el9.x86_64.rpm | SHA-256: 5d0fe289cd28f5d91c8b89ac6885bf36bd5240b0b4a3217a9fa27c6ca08f43cc |
| openssl-perl-3.5.1-3.el9.x86_64.rpm | SHA-256: b0c129c645d8d3d79379bc6415b0bc609d6ce104ca36b28f1d1fb8cfc3212b9b |
Red Hat Enterprise Linux for IBM z Systems 9
| SRPM | |
|---|---|
| openssl-3.5.1-3.el9.src.rpm | SHA-256: 68c2409b36474e010052c30e30c0b0607f12dea8042e08fa77835e5d5bdec761 |
| openssl-fips-provider-3.0.7-8.el9.src.rpm | SHA-256: f6e518e04053c5ff00bea751cd9bad3bd7a2be0eb8259b9d45b3cf1a80438bb9 |
| s390x | |
| openssl-3.5.1-3.el9.s390x.rpm | SHA-256: 5fa69ec97e313e906e2171aeea0c47ab09ecd7aee0f5792cc40cf53a7ba4c17f |
| openssl-debuginfo-3.5.1-3.el9.s390x.rpm | SHA-256: b766b8abd8f126500bcf9eddd884ed5837ed01d9fa9ba30884b17dd2799332f9 |
| openssl-debuginfo-3.5.1-3.el9.s390x.rpm | SHA-256: b766b8abd8f126500bcf9eddd884ed5837ed01d9fa9ba30884b17dd2799332f9 |
| openssl-debugsource-3.5.1-3.el9.s390x.rpm | SHA-256: c6c65605818d60f5add521b32a80b04db7e4091547aee2e394a67d104aa5f079 |
| openssl-debugsource-3.5.1-3.el9.s390x.rpm | SHA-256: c6c65605818d60f5add521b32a80b04db7e4091547aee2e394a67d104aa5f079 |
| openssl-devel-3.5.1-3.el9.s390x.rpm | SHA-256: 32f45915fa312dab8ce30c1fcf7f363fa73cb0fa0482a42699cfe2cd80c6a8c3 |
| openssl-fips-provider-3.0.7-8.el9.s390x.rpm | SHA-256: 8a4bc9f39ece3d6841a46681c0cdc7ca8510590057e486939b6d0cc1aace958d |
| openssl-fips-provider-so-3.0.7-8.el9.s390x.rpm | SHA-256: 612f812c248e7cf6d86de00a2e670d74233bd1da20d45a68dd09527dc0547f10 |
| openssl-fips-provider-so-debuginfo-3.0.7-8.el9.s390x.rpm | SHA-256: ffeb567badfcc3e6dcf6c9bebcfbdd938ea8677acaa0f0e9951d2f61b6de8cd7 |
| openssl-fips-provider-so-debugsource-3.0.7-8.el9.s390x.rpm | SHA-256: 5da76dfbe163d7fa5652cf9fe9572b278334ba3aecee202c38662ec3ea9a2e55 |
| openssl-libs-3.5.1-3.el9.s390x.rpm | SHA-256: 3b2c9ad822f0e1b7698d620b9d738c0a0f8ca912271dff4f1cbe255229caa9b0 |
| openssl-libs-debuginfo-3.5.1-3.el9.s390x.rpm | SHA-256: f09de4cfb858f2c6392789f97b150534ae092d59540a3bea7f8ea8e3494eda6d |
| openssl-libs-debuginfo-3.5.1-3.el9.s390x.rpm | SHA-256: f09de4cfb858f2c6392789f97b150534ae092d59540a3bea7f8ea8e3494eda6d |
| openssl-perl-3.5.1-3.el9.s390x.rpm | SHA-256: 97c756725675f28dd8a224315be1c1e7e18996dc145bcd32b485bf9b6bfd2170 |
Red Hat Enterprise Linux for Power, little endian 9
| SRPM | |
|---|---|
| openssl-3.5.1-3.el9.src.rpm | SHA-256: 68c2409b36474e010052c30e30c0b0607f12dea8042e08fa77835e5d5bdec761 |
| openssl-fips-provider-3.0.7-8.el9.src.rpm | SHA-256: f6e518e04053c5ff00bea751cd9bad3bd7a2be0eb8259b9d45b3cf1a80438bb9 |
| ppc64le | |
| openssl-3.5.1-3.el9.ppc64le.rpm | SHA-256: c1dd6e34e5e8047ced3d3f9782ee740943c4c77188dbc68986d300d6fafc0a8e |
| openssl-debuginfo-3.5.1-3.el9.ppc64le.rpm | SHA-256: f9737af7a8415136c9baa88458042f44cdcc2af4809a5bae65937c886e59a315 |
| openssl-debuginfo-3.5.1-3.el9.ppc64le.rpm | SHA-256: f9737af7a8415136c9baa88458042f44cdcc2af4809a5bae65937c886e59a315 |
| openssl-debugsource-3.5.1-3.el9.ppc64le.rpm | SHA-256: b7cb23862b6b7119666d5a0fb8f77c4f9bf2d6fb73b12b02d6730036b4af7d12 |
| openssl-debugsource-3.5.1-3.el9.ppc64le.rpm | SHA-256: b7cb23862b6b7119666d5a0fb8f77c4f9bf2d6fb73b12b02d6730036b4af7d12 |
| openssl-devel-3.5.1-3.el9.ppc64le.rpm | SHA-256: 24da1df346cd836c83cb6f9f481a1c96abd42415819238aa2a28d5d30aa35b89 |
| openssl-fips-provider-3.0.7-8.el9.ppc64le.rpm | SHA-256: c4a55a68f123fd873380d919ede200fb64f7443eb4235ce555a307cfee9fb6a5 |
| openssl-fips-provider-so-3.0.7-8.el9.ppc64le.rpm | SHA-256: 325a2017d21f5ca789931de321cd9fb5f359ce12fb0d0acc2f3cd9dc00b00dc3 |
| openssl-fips-provider-so-debuginfo-3.0.7-8.el9.ppc64le.rpm | SHA-256: 5103d099f5c90cafbbf7466ad90a012fc276a13d23e526e2cd8e00a5b3a69d0f |
| openssl-fips-provider-so-debugsource-3.0.7-8.el9.ppc64le.rpm | SHA-256: 4673d59722c76fbd83012b460c999622c03116b6852eec5d3da6da3f49f80289 |
| openssl-libs-3.5.1-3.el9.ppc64le.rpm | SHA-256: bc2968abbbbcdbaaf8561525163d0097c7ffec868a93d7423b5a679332d1e475 |
| openssl-libs-debuginfo-3.5.1-3.el9.ppc64le.rpm | SHA-256: 8c499cd90aec3ecf12706f6b55a819d4e79da6a76f6757d6f45ac5decb8ddc84 |
| openssl-libs-debuginfo-3.5.1-3.el9.ppc64le.rpm | SHA-256: 8c499cd90aec3ecf12706f6b55a819d4e79da6a76f6757d6f45ac5decb8ddc84 |
| openssl-perl-3.5.1-3.el9.ppc64le.rpm | SHA-256: 31b475ae22ca649ab775c8afa00f7ed13457db1d2b1edafbd055d45763bc8555 |
Red Hat Enterprise Linux for ARM 64 9
| SRPM | |
|---|---|
| openssl-3.5.1-3.el9.src.rpm | SHA-256: 68c2409b36474e010052c30e30c0b0607f12dea8042e08fa77835e5d5bdec761 |
| openssl-fips-provider-3.0.7-8.el9.src.rpm | SHA-256: f6e518e04053c5ff00bea751cd9bad3bd7a2be0eb8259b9d45b3cf1a80438bb9 |
| aarch64 | |
| openssl-3.5.1-3.el9.aarch64.rpm | SHA-256: 3a138cc8326c5e63d64b283ff063f30b24ecaf709bc33640fa2431f1e1203a7b |
| openssl-debuginfo-3.5.1-3.el9.aarch64.rpm | SHA-256: e9a36daf290d93d35b0871aec7a9ad66b605ae5859b4cf18c70b6a7f58d2f5fc |
| openssl-debuginfo-3.5.1-3.el9.aarch64.rpm | SHA-256: e9a36daf290d93d35b0871aec7a9ad66b605ae5859b4cf18c70b6a7f58d2f5fc |
| openssl-debugsource-3.5.1-3.el9.aarch64.rpm | SHA-256: 87005ff5fdb123115adc855c5d9560f3480974aca8242910f5dc84ccf2304f60 |
| openssl-debugsource-3.5.1-3.el9.aarch64.rpm | SHA-256: 87005ff5fdb123115adc855c5d9560f3480974aca8242910f5dc84ccf2304f60 |
| openssl-devel-3.5.1-3.el9.aarch64.rpm | SHA-256: 51dee84ef4583f4ab20f1663eba29705cb335cfd3829e8b305387b23a3bb5230 |
| openssl-fips-provider-3.0.7-8.el9.aarch64.rpm | SHA-256: 0cfe7b281ae2ca3cb0ceaa1a0b84f8c087c4ac16662ebb9c19b5681cf39f99a9 |
| openssl-fips-provider-so-3.0.7-8.el9.aarch64.rpm | SHA-256: 18c77b9b37e7abf0e8cf1dac4b3de770efe895547bdcab8aea8d8d8592954947 |
| openssl-fips-provider-so-debuginfo-3.0.7-8.el9.aarch64.rpm | SHA-256: 26ead75645fdfad5a715fe8fe09c2e2085a07a7e465af13c0dfac4aa97dbe584 |
| openssl-fips-provider-so-debugsource-3.0.7-8.el9.aarch64.rpm | SHA-256: 11e56a8f33a74bd85c836c89c2b729015756e1801649c0a177e7a3ea942133d8 |
| openssl-libs-3.5.1-3.el9.aarch64.rpm | SHA-256: 266011ffe116a891e24f56d23da5804ceee9c4d9f697936056b6240ee2a638ea |
| openssl-libs-debuginfo-3.5.1-3.el9.aarch64.rpm | SHA-256: 169855a3d446e532e37f9f706ff59aba28ad068bb9645774e3f41d83cdfba740 |
| openssl-libs-debuginfo-3.5.1-3.el9.aarch64.rpm | SHA-256: 169855a3d446e532e37f9f706ff59aba28ad068bb9645774e3f41d83cdfba740 |
| openssl-perl-3.5.1-3.el9.aarch64.rpm | SHA-256: 389ef18e921b760028a1d4ce4380c0c57c4732d21120e87222bf6bf4f84baadd |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.