Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22794 - Security Advisory
Issued:
2025-12-08
Updated:
2025-12-08

RHSA-2025:22794 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: openssl security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openssl is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Security Fix(es):

  • openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64

Fixes

  • BZ - 2396054 - CVE-2025-9230 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap

CVEs

  • CVE-2025-9230

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0

SRPM
openssl-3.2.2-16.el10_0.5.src.rpm SHA-256: 7f7e84aa08c564df549959a6734d4a34acba7158446e424c6d0edafb9f16dd1b
x86_64
openssl-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: f1a7b61982ab123ddcfa6f5254040e1d55e0fe7c8cda858c24a2ccd744b15f60
openssl-debuginfo-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: e8c62904f9218f09a1d5d0e460826607052096a5374cd0104a3bc684a1201dc7
openssl-debuginfo-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: e8c62904f9218f09a1d5d0e460826607052096a5374cd0104a3bc684a1201dc7
openssl-debugsource-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: c54b154ae7496b8d142b3d1e907bf40fa8cb8964ba1651004399ddff343f3bee
openssl-debugsource-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: c54b154ae7496b8d142b3d1e907bf40fa8cb8964ba1651004399ddff343f3bee
openssl-devel-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: a7f49f40567b725d61d62306a594c64d4fdaa23959148ae7f78fa9bb54438925
openssl-libs-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: a86521378c7e45461d51e104f9927786f05681592052129c11935cecd8cfa114
openssl-libs-debuginfo-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: 4a4adb34314660099c73e008a66667226c67a2d0b08dc21eaac0213d2b8f66c1
openssl-libs-debuginfo-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: 4a4adb34314660099c73e008a66667226c67a2d0b08dc21eaac0213d2b8f66c1
openssl-perl-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: 380afb57503ebf7b5686861bcc026e7eb4da3779ca988736238c2876647e3759

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0

SRPM
openssl-3.2.2-16.el10_0.5.src.rpm SHA-256: 7f7e84aa08c564df549959a6734d4a34acba7158446e424c6d0edafb9f16dd1b
s390x
openssl-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 8d9b567ae3916780f7505a844de5f803e2098b06f808a2660bc3081324f2bfd7
openssl-debuginfo-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 7bf5cf07f3ea05e20ecdefca6063c97b31f110d82e46d8f9d4fef713bbae5d10
openssl-debuginfo-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 7bf5cf07f3ea05e20ecdefca6063c97b31f110d82e46d8f9d4fef713bbae5d10
openssl-debugsource-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 437c271d9045b417cb4bc0e441afdc0297b86176f4bee2396cfa9fe1b216a032
openssl-debugsource-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 437c271d9045b417cb4bc0e441afdc0297b86176f4bee2396cfa9fe1b216a032
openssl-devel-3.2.2-16.el10_0.5.s390x.rpm SHA-256: ae05385a3144c4f806face5aaf3a5f509c8d57ced4ea72b9126a254da77c1554
openssl-libs-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 611d6538058a376b95b4fb7e6eb2d0718928cec24dd26bee776287d8c62e644c
openssl-libs-debuginfo-3.2.2-16.el10_0.5.s390x.rpm SHA-256: aeb8ec89d7cd41b6bfd83dbb79c5336541658259ca63113a00d3569e6e0c6acc
openssl-libs-debuginfo-3.2.2-16.el10_0.5.s390x.rpm SHA-256: aeb8ec89d7cd41b6bfd83dbb79c5336541658259ca63113a00d3569e6e0c6acc
openssl-perl-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 3c266d18e3094c7b65fff537d1272f9531c30ddf06dcc5d9b90b82284250fdc5

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0

SRPM
openssl-3.2.2-16.el10_0.5.src.rpm SHA-256: 7f7e84aa08c564df549959a6734d4a34acba7158446e424c6d0edafb9f16dd1b
ppc64le
openssl-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 6ae413349dcba8a39bdd81a7adfa42227deacf3eb36646504eeacf1cd61bcf2e
openssl-debuginfo-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: f4ea934db5fd5ba2e1f50041d94503720da622cf36621c9d7a80811aedd4b9fd
openssl-debuginfo-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: f4ea934db5fd5ba2e1f50041d94503720da622cf36621c9d7a80811aedd4b9fd
openssl-debugsource-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 0d595ae6805aa22589ece5fd0b4802a49e0bcd49f06946c5882dca131a48ee5c
openssl-debugsource-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 0d595ae6805aa22589ece5fd0b4802a49e0bcd49f06946c5882dca131a48ee5c
openssl-devel-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: dae21a5d75843662ab5ddd0f16cf7d554009d3b5e6e8ebadcf4c922661d139a7
openssl-libs-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: f49da7821a775db585b57f23a9febdb79f94445294399b986bca0cd456e11b1e
openssl-libs-debuginfo-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 6412331f91bad98f8b913e1db818110203c3551b939dc0328e6f47e79e0cb8d1
openssl-libs-debuginfo-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 6412331f91bad98f8b913e1db818110203c3551b939dc0328e6f47e79e0cb8d1
openssl-perl-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 8012cf9a22f87d22b0b176e8a9988ff7742fd9ae44bec4e5adca0849632ed5fa

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0

SRPM
openssl-3.2.2-16.el10_0.5.src.rpm SHA-256: 7f7e84aa08c564df549959a6734d4a34acba7158446e424c6d0edafb9f16dd1b
aarch64
openssl-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: fd2b3b15659ed10881d1c486a89819f20774c828c5306d892ab7e292fdac801d
openssl-debuginfo-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 2a684da491e14506ee00a823320109f688a946b5a58a853a45dfbab6c0f791b8
openssl-debuginfo-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 2a684da491e14506ee00a823320109f688a946b5a58a853a45dfbab6c0f791b8
openssl-debugsource-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: d54e179381843728db2b9bde8eb682bb3971d62b282e291cf83b31b0283e8a61
openssl-debugsource-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: d54e179381843728db2b9bde8eb682bb3971d62b282e291cf83b31b0283e8a61
openssl-devel-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 136f8fe64bbe0daa50eeef921598c9a42c245eb12a2940275155c526130f39d2
openssl-libs-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: b8776d78db4c976301f048f6c836f6b1c8ed530a0f9d573549e48285a80b5324
openssl-libs-debuginfo-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 730fedbe0ba52888f737b11c9a24802c529f8ecc0509b8dd07b1fc124837239a
openssl-libs-debuginfo-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 730fedbe0ba52888f737b11c9a24802c529f8ecc0509b8dd07b1fc124837239a
openssl-perl-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: b8607ea8afb192b756b49d0f18c4e88067af27274113f1da1836d47199817d1b

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0

SRPM
openssl-3.2.2-16.el10_0.5.src.rpm SHA-256: 7f7e84aa08c564df549959a6734d4a34acba7158446e424c6d0edafb9f16dd1b
aarch64
openssl-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: fd2b3b15659ed10881d1c486a89819f20774c828c5306d892ab7e292fdac801d
openssl-debuginfo-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 2a684da491e14506ee00a823320109f688a946b5a58a853a45dfbab6c0f791b8
openssl-debuginfo-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 2a684da491e14506ee00a823320109f688a946b5a58a853a45dfbab6c0f791b8
openssl-debugsource-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: d54e179381843728db2b9bde8eb682bb3971d62b282e291cf83b31b0283e8a61
openssl-debugsource-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: d54e179381843728db2b9bde8eb682bb3971d62b282e291cf83b31b0283e8a61
openssl-devel-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 136f8fe64bbe0daa50eeef921598c9a42c245eb12a2940275155c526130f39d2
openssl-libs-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: b8776d78db4c976301f048f6c836f6b1c8ed530a0f9d573549e48285a80b5324
openssl-libs-debuginfo-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 730fedbe0ba52888f737b11c9a24802c529f8ecc0509b8dd07b1fc124837239a
openssl-libs-debuginfo-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: 730fedbe0ba52888f737b11c9a24802c529f8ecc0509b8dd07b1fc124837239a
openssl-perl-3.2.2-16.el10_0.5.aarch64.rpm SHA-256: b8607ea8afb192b756b49d0f18c4e88067af27274113f1da1836d47199817d1b

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0

SRPM
openssl-3.2.2-16.el10_0.5.src.rpm SHA-256: 7f7e84aa08c564df549959a6734d4a34acba7158446e424c6d0edafb9f16dd1b
s390x
openssl-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 8d9b567ae3916780f7505a844de5f803e2098b06f808a2660bc3081324f2bfd7
openssl-debuginfo-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 7bf5cf07f3ea05e20ecdefca6063c97b31f110d82e46d8f9d4fef713bbae5d10
openssl-debuginfo-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 7bf5cf07f3ea05e20ecdefca6063c97b31f110d82e46d8f9d4fef713bbae5d10
openssl-debugsource-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 437c271d9045b417cb4bc0e441afdc0297b86176f4bee2396cfa9fe1b216a032
openssl-debugsource-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 437c271d9045b417cb4bc0e441afdc0297b86176f4bee2396cfa9fe1b216a032
openssl-devel-3.2.2-16.el10_0.5.s390x.rpm SHA-256: ae05385a3144c4f806face5aaf3a5f509c8d57ced4ea72b9126a254da77c1554
openssl-libs-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 611d6538058a376b95b4fb7e6eb2d0718928cec24dd26bee776287d8c62e644c
openssl-libs-debuginfo-3.2.2-16.el10_0.5.s390x.rpm SHA-256: aeb8ec89d7cd41b6bfd83dbb79c5336541658259ca63113a00d3569e6e0c6acc
openssl-libs-debuginfo-3.2.2-16.el10_0.5.s390x.rpm SHA-256: aeb8ec89d7cd41b6bfd83dbb79c5336541658259ca63113a00d3569e6e0c6acc
openssl-perl-3.2.2-16.el10_0.5.s390x.rpm SHA-256: 3c266d18e3094c7b65fff537d1272f9531c30ddf06dcc5d9b90b82284250fdc5

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0

SRPM
openssl-3.2.2-16.el10_0.5.src.rpm SHA-256: 7f7e84aa08c564df549959a6734d4a34acba7158446e424c6d0edafb9f16dd1b
ppc64le
openssl-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 6ae413349dcba8a39bdd81a7adfa42227deacf3eb36646504eeacf1cd61bcf2e
openssl-debuginfo-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: f4ea934db5fd5ba2e1f50041d94503720da622cf36621c9d7a80811aedd4b9fd
openssl-debuginfo-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: f4ea934db5fd5ba2e1f50041d94503720da622cf36621c9d7a80811aedd4b9fd
openssl-debugsource-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 0d595ae6805aa22589ece5fd0b4802a49e0bcd49f06946c5882dca131a48ee5c
openssl-debugsource-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 0d595ae6805aa22589ece5fd0b4802a49e0bcd49f06946c5882dca131a48ee5c
openssl-devel-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: dae21a5d75843662ab5ddd0f16cf7d554009d3b5e6e8ebadcf4c922661d139a7
openssl-libs-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: f49da7821a775db585b57f23a9febdb79f94445294399b986bca0cd456e11b1e
openssl-libs-debuginfo-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 6412331f91bad98f8b913e1db818110203c3551b939dc0328e6f47e79e0cb8d1
openssl-libs-debuginfo-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 6412331f91bad98f8b913e1db818110203c3551b939dc0328e6f47e79e0cb8d1
openssl-perl-3.2.2-16.el10_0.5.ppc64le.rpm SHA-256: 8012cf9a22f87d22b0b176e8a9988ff7742fd9ae44bec4e5adca0849632ed5fa

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0

SRPM
openssl-3.2.2-16.el10_0.5.src.rpm SHA-256: 7f7e84aa08c564df549959a6734d4a34acba7158446e424c6d0edafb9f16dd1b
x86_64
openssl-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: f1a7b61982ab123ddcfa6f5254040e1d55e0fe7c8cda858c24a2ccd744b15f60
openssl-debuginfo-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: e8c62904f9218f09a1d5d0e460826607052096a5374cd0104a3bc684a1201dc7
openssl-debuginfo-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: e8c62904f9218f09a1d5d0e460826607052096a5374cd0104a3bc684a1201dc7
openssl-debugsource-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: c54b154ae7496b8d142b3d1e907bf40fa8cb8964ba1651004399ddff343f3bee
openssl-debugsource-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: c54b154ae7496b8d142b3d1e907bf40fa8cb8964ba1651004399ddff343f3bee
openssl-devel-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: a7f49f40567b725d61d62306a594c64d4fdaa23959148ae7f78fa9bb54438925
openssl-libs-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: a86521378c7e45461d51e104f9927786f05681592052129c11935cecd8cfa114
openssl-libs-debuginfo-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: 4a4adb34314660099c73e008a66667226c67a2d0b08dc21eaac0213d2b8f66c1
openssl-libs-debuginfo-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: 4a4adb34314660099c73e008a66667226c67a2d0b08dc21eaac0213d2b8f66c1
openssl-perl-3.2.2-16.el10_0.5.x86_64.rpm SHA-256: 380afb57503ebf7b5686861bcc026e7eb4da3779ca988736238c2876647e3759

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility