Red Hat Customer Portal

Skip to main content

Main Navigation

  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Automation Platform
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat Advanced Cluster Management for Kubernetes
      • Red Hat Quay
      • Red Hat CodeReady Workspaces
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • Runtimes
      • Back
      • Red Hat Runtimes
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat Data Grid
      • Red Hat JBoss Web Server
      • Red Hat Single Sign On
      • Red Hat support for Spring Boot
      • Red Hat build of Node.js
      • Red Hat build of Thorntail
      • Red Hat build of Eclipse Vert.x
      • Red Hat build of OpenJDK
      • Red Hat build of Quarkus
      • Red Hat CodeReady Studio
    • Integration and Automation
      • Back
      • Red Hat Integration
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat 3scale API Management
      • Red Hat JBoss Data Virtualization
      • Red Hat Process Automation
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
    • Support
    • Production Support
    • Development Support
    • Product Life Cycles
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem Catalog
    • Partner Resources
    • Red Hat in the Public Cloud
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Troubleshoot a product issue
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • 한국어
    • 日本語
    • 中文 (中国)
Red Hat Customer Portal
  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Automation Platform
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat Advanced Cluster Management for Kubernetes
      • Red Hat Quay
      • Red Hat CodeReady Workspaces
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • Runtimes
      • Back
      • Red Hat Runtimes
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat Data Grid
      • Red Hat JBoss Web Server
      • Red Hat Single Sign On
      • Red Hat support for Spring Boot
      • Red Hat build of Node.js
      • Red Hat build of Thorntail
      • Red Hat build of Eclipse Vert.x
      • Red Hat build of OpenJDK
      • Red Hat build of Quarkus
      • Red Hat CodeReady Studio
    • Integration and Automation
      • Back
      • Red Hat Integration
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat 3scale API Management
      • Red Hat JBoss Data Virtualization
      • Red Hat Process Automation
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
    • Support
    • Production Support
    • Development Support
    • Product Life Cycles
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem Catalog
    • Partner Resources
    • Red Hat in the Public Cloud
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Troubleshoot a product issue
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • 한국어
    • 日本語
    • 中文 (中国)
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Search
  • Log In
  • Language
Or troubleshoot an issue.

Log in to Your Red Hat Account

Log In

Your Red Hat account gives you access to your profile, preferences, and services, depending on your status.

Register

If you are a new customer, register now for access to product evaluations and purchasing capabilities.

Need access to an account?

If your company has an existing Red Hat account, your organization administrator can grant you access.

If you have any questions, please contact customer service.

Red Hat Account Number:

Red Hat Account

  • Account Details
  • User Management
  • Account Maintenance
  • Account Team

Customer Portal

  • My Profile
  • Notifications
  • Help

For your security, if you’re on a public computer and have finished using your Red Hat services, please be sure to log out.

Log Out

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)
Red Hat Customer Portal Red Hat Customer Portal
  • Products & Services
  • Tools
  • Security
  • Community
  • Infrastructure and Management

  • Cloud Computing

  • Storage

  • Runtimes

  • Integration and Automation

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat CodeReady Workspaces
  • Red Hat OpenShift Service on AWS
  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat Openshift Container Storage
  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus
  • Red Hat CodeReady Studio
  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
View All Products
  • Support
  • Production Support
  • Development Support
  • Product Life Cycles

Services

  • Consulting
  • Technical Account Management
  • Training & Certifications
  • Documentation
  • Red Hat Enterprise Linux
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Ecosystem Catalog
  • Red Hat in the Public Cloud
  • Partner Resources

Tools

  • Troubleshoot a product issue
  • Packages
  • Errata
  • Customer Portal Labs
  • Configuration
  • Deployment
  • Security
  • Troubleshooting

Red Hat Insights

Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

  • Learn more
  • Go to Insights

Red Hat Product Security Center

Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

Product Security Center

Security Updates

  • Security Advisories
  • Red Hat CVE Database
  • Security Labs

Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

  • View Responses

Resources

  • Overview
  • Security Blog
  • Security Measurement
  • Severity Ratings
  • Backporting Policies
  • Product Signing (GPG) Keys

Customer Portal Community

  • Discussions
  • Blogs
  • Private Groups
  • Community Activity

Customer Events

  • Red Hat Convergence
  • Red Hat Summit

Stories

  • Red Hat Subscription Value
  • You Asked. We Acted.
  • Open Source Communities
Red Hat Product Errata RHSA-2021:1024 - Security Advisory
Issued:
2021-03-29
Updated:
2021-03-29

RHSA-2021:1024 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: openssl security update

Type/Severity

Security Advisory: Important

Topic

An update for openssl is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Security Fix(es):

  • openssl: NULL pointer dereference in signature_algorithms processing (CVE-2021-3449)
  • openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT (CVE-2021-3450)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted.

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 1941547 - CVE-2021-3450 openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
  • BZ - 1941554 - CVE-2021-3449 openssl: NULL pointer dereference in signature_algorithms processing

CVEs

  • CVE-2021-3449
  • CVE-2021-3450

References

  • https://access.redhat.com/security/updates/classification/#important
  • Note: More recent versions of these packages may be available. Click a package name for more details.

    Red Hat Enterprise Linux for x86_64 8

    SRPM
    openssl-1.1.1g-15.el8_3.src.rpm SHA-256: 6211d017f5abc92681fe4d45eccc5d4fee52b66130d3c34a5fe8293ea96f4b05
    x86_64
    openssl-1.1.1g-15.el8_3.x86_64.rpm SHA-256: 75f7d3db07ab52daef3ec3211b7d8ad801de0a8f5585d36fe2917614152fb2c8
    openssl-debuginfo-1.1.1g-15.el8_3.i686.rpm SHA-256: 61f588f565a173a55dc007351954284470a8e4e4b5dca7db1fd019bf27d64d23
    openssl-debuginfo-1.1.1g-15.el8_3.x86_64.rpm SHA-256: c49018f795e6463615d6b410fad9e9d3ca2a80a09facc8854d490404bd1c9a18
    openssl-debugsource-1.1.1g-15.el8_3.i686.rpm SHA-256: 1515ff619cdb0547e4b2d7c4610eaa048bdb83480f8a84ddbf7da0758de1e463
    openssl-debugsource-1.1.1g-15.el8_3.x86_64.rpm SHA-256: 5a04c3640d1e33aa98bada35d86bc0991c586b0c818a0c8d35e1c753ffc8a795
    openssl-devel-1.1.1g-15.el8_3.i686.rpm SHA-256: 3b88aa1963e015c95aa8d6a8bcef13bf36ee50f206ecd0050219dc864e61b28b
    openssl-devel-1.1.1g-15.el8_3.x86_64.rpm SHA-256: b6491db41e3b7e68589e25191680851c7f07774d8b0cda27e0dbc6af326519ac
    openssl-libs-1.1.1g-15.el8_3.i686.rpm SHA-256: f3e0d269a38368868164347279b246803d300c47967e638dc3f35f3e8bc2d7b1
    openssl-libs-1.1.1g-15.el8_3.x86_64.rpm SHA-256: 7f4ffa37a0fdc0b7de2fceca3aa2301678368bf3ac924981beb4d7232c2f465d
    openssl-libs-debuginfo-1.1.1g-15.el8_3.i686.rpm SHA-256: a686f402f73105d802cfdc0fb652956b720e458ee6c72928d32d95fe86b3d19d
    openssl-libs-debuginfo-1.1.1g-15.el8_3.x86_64.rpm SHA-256: 3fbd334c90808d44a560c7ed340b668c0afc61fad5f3a508e5f1e5adb5008d65
    openssl-perl-1.1.1g-15.el8_3.x86_64.rpm SHA-256: 482aaa4f929a9001d9cfd1fee001000b018227df703e932e06ee23f11b2619d2

    Red Hat Enterprise Linux for IBM z Systems 8

    SRPM
    openssl-1.1.1g-15.el8_3.src.rpm SHA-256: 6211d017f5abc92681fe4d45eccc5d4fee52b66130d3c34a5fe8293ea96f4b05
    s390x
    openssl-1.1.1g-15.el8_3.s390x.rpm SHA-256: 87b9879f5888c2fa8f1155092d3f89c4ae182261329c3d9b00d341609ee26459
    openssl-debuginfo-1.1.1g-15.el8_3.s390x.rpm SHA-256: c089a0a27d036cc9bd9f0550337ccba0d293df105c5d0f7f397cf3fd2d74a3c7
    openssl-debugsource-1.1.1g-15.el8_3.s390x.rpm SHA-256: 17e59ca14879b98f3dcf84dc167b2e0846f09bace9690b0520d253e845fc6e23
    openssl-devel-1.1.1g-15.el8_3.s390x.rpm SHA-256: bb1ed4f665a1295da9c6f39644b0a242863b60e7c40a51d7fa50ed59bc026e6a
    openssl-libs-1.1.1g-15.el8_3.s390x.rpm SHA-256: 2ce3beef8f6ab944bdc19841b9be60d2edc43ff4be9d04177f6c3c102cd8c623
    openssl-libs-debuginfo-1.1.1g-15.el8_3.s390x.rpm SHA-256: c51edbaedb409d4591d16467bafaa582139053cff7397301e971500f2adbfe95
    openssl-perl-1.1.1g-15.el8_3.s390x.rpm SHA-256: 3157464eb4af719ac88d752953e68d1933802dfd0f65c35c82f622b71c5a2903

    Red Hat Enterprise Linux for Power, little endian 8

    SRPM
    openssl-1.1.1g-15.el8_3.src.rpm SHA-256: 6211d017f5abc92681fe4d45eccc5d4fee52b66130d3c34a5fe8293ea96f4b05
    ppc64le
    openssl-1.1.1g-15.el8_3.ppc64le.rpm SHA-256: a0779a7bd1999cf900380e9880568828366f1ac16f59b5bfdbd60d8ac3fe7330
    openssl-debuginfo-1.1.1g-15.el8_3.ppc64le.rpm SHA-256: da1ae39f629c80c29d2c886659778cf27d0de2fb683c4b7a140e1d710c800734
    openssl-debugsource-1.1.1g-15.el8_3.ppc64le.rpm SHA-256: dea9ea6af83fda70eeaa8951f65f98e4ebd1a1d7972e15cacc407f228dfb9000
    openssl-devel-1.1.1g-15.el8_3.ppc64le.rpm SHA-256: f67e5ebe4aab1a7d17e79c8bcb5ad73fa26bab7b40c1ce293aa3050df4f7189b
    openssl-libs-1.1.1g-15.el8_3.ppc64le.rpm SHA-256: f52a508f20e762f18dd462ffbe2b4ce60aff8e37a5a5c3e107eaa4329cd31973
    openssl-libs-debuginfo-1.1.1g-15.el8_3.ppc64le.rpm SHA-256: 753339422f9c8269db5644b5eb1c44f90e6f07eb2eecac54bf89b7a81ad51ddf
    openssl-perl-1.1.1g-15.el8_3.ppc64le.rpm SHA-256: 9525744d8bebdf7aa28ab4d1fd29df9d32b57d939bc6cef40eae04745fbd953f

    Red Hat Enterprise Linux for ARM 64 8

    SRPM
    openssl-1.1.1g-15.el8_3.src.rpm SHA-256: 6211d017f5abc92681fe4d45eccc5d4fee52b66130d3c34a5fe8293ea96f4b05
    aarch64
    openssl-1.1.1g-15.el8_3.aarch64.rpm SHA-256: e511a8a5a9d4519414c5b49dfaa217ec525ecc753452bea0f19b5fa0ea33ea88
    openssl-debuginfo-1.1.1g-15.el8_3.aarch64.rpm SHA-256: b491cc5a9ea7346f5cb7ff6d7d2b92cea13ad6166b1837a2d7d39b5b30abbfcb
    openssl-debugsource-1.1.1g-15.el8_3.aarch64.rpm SHA-256: f445f9865ff95d672ad6aaafb10bafbee1361ebb7be01a7b8a6af1e0bef360e2
    openssl-devel-1.1.1g-15.el8_3.aarch64.rpm SHA-256: 0a3449fa8e19b1812bcdecba9656ac6e3959d2bba66486fc98a672ea79a16e2e
    openssl-libs-1.1.1g-15.el8_3.aarch64.rpm SHA-256: 2dd6239fe810334d90f28e5e73a2a3b2a11f02c74e668e8eb0b5c6eb809e8bcc
    openssl-libs-debuginfo-1.1.1g-15.el8_3.aarch64.rpm SHA-256: b37c2c7deb9147075d57b6b08c1a6335abc9c45577135948e5ccd89659d21588
    openssl-perl-1.1.1g-15.el8_3.aarch64.rpm SHA-256: 60ee44222dbe2241fe1d15b8f0d208dbe0f327db3fa3dad8e76247e0711ba462

    The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

    Red Hat

    Quick Links

    • Downloads
    • Subscriptions
    • Support Cases
    • Customer Service
    • Product Documentation

    Help

    • Contact Us
    • Customer Portal FAQ
    • Log-in Assistance

    Site Info

    • Trust Red Hat
    • Browser Support Policy
    • Accessibility
    • Awards and Recognition
    • Colophon

    Related Sites

    • redhat.com
    • openshift.com
    • developers.redhat.com
    • connect.redhat.com
    • cloud.redhat.com

    About

    • Red Hat Subscription Value
    • About Red Hat
    • Red Hat Jobs
    Copyright © 2021 Red Hat, Inc.
    • Privacy Statement
    • Customer Portal Terms of Use
    • All Policies and Guidelines
    Red Hat Summit
    Twitter Facebook