Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:1720 - Security Advisory
Issued:
2026-02-02
Updated:
2026-02-02

RHSA-2026:1720 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: openssl security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openssl is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Security Fix(es):

  • openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2396054 - CVE-2025-9230 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap

CVEs

  • CVE-2025-9230

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
openssl-1.0.2k-26.el7_9.1.src.rpm SHA-256: e91340c5594a2a613a032cfa9e75ecb258905384b24dc60ff021ba4c1b3746c5
x86_64
openssl-1.0.2k-26.el7_9.1.x86_64.rpm SHA-256: 95d17fdc3799929cc27901f886e4219cb0ee01e8bc6bf1547bedb9b8f02e0b61
openssl-debuginfo-1.0.2k-26.el7_9.1.i686.rpm SHA-256: e9d74a194916e2b2611ef58a3f6a53cf3fe481b61aa4ab06dbac9042c5d2ce0f
openssl-debuginfo-1.0.2k-26.el7_9.1.i686.rpm SHA-256: e9d74a194916e2b2611ef58a3f6a53cf3fe481b61aa4ab06dbac9042c5d2ce0f
openssl-debuginfo-1.0.2k-26.el7_9.1.x86_64.rpm SHA-256: ba6ce3e9afe3c33a3e3e207df4d32e38e8f3c0b6871a6a046fa442ffe94355cc
openssl-debuginfo-1.0.2k-26.el7_9.1.x86_64.rpm SHA-256: ba6ce3e9afe3c33a3e3e207df4d32e38e8f3c0b6871a6a046fa442ffe94355cc
openssl-devel-1.0.2k-26.el7_9.1.i686.rpm SHA-256: 3c483f13a7b0db48dfab883fed85d504b7230e6fe9e2f28f168fbe41ff4cddba
openssl-devel-1.0.2k-26.el7_9.1.x86_64.rpm SHA-256: 60c4e22aef5a6a269bc08e40f5755e936feab3bc03c54ccb6365c7e6a3ec3e6a
openssl-libs-1.0.2k-26.el7_9.1.i686.rpm SHA-256: 211bd415db6eef994d42dc96827698eee6fcd022f801c875813344bdac4e4a66
openssl-libs-1.0.2k-26.el7_9.1.x86_64.rpm SHA-256: 77878c917c5f515584b13e5c28ed6b9886a41a82f3b37f67554b6c1225eaf177
openssl-perl-1.0.2k-26.el7_9.1.x86_64.rpm SHA-256: 9de804e3d7ad21c2047afae4e61977c283e6f4d2e1825b9f504ab77e304676a8
openssl-static-1.0.2k-26.el7_9.1.i686.rpm SHA-256: 680edd6e97027939754965d032cfb0a265ff48a7a3f31c7a5f473ec46127e394
openssl-static-1.0.2k-26.el7_9.1.x86_64.rpm SHA-256: e53d19105746f329863dccdb753022b397fbca83dfc6eebec38dbe5c5b9a1940

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
openssl-1.0.2k-26.el7_9.1.src.rpm SHA-256: e91340c5594a2a613a032cfa9e75ecb258905384b24dc60ff021ba4c1b3746c5
s390x
openssl-1.0.2k-26.el7_9.1.s390x.rpm SHA-256: 74073979acb8d3648a2b9f0b3c79af29845e886b0bf5d3d3a80cbba7dfa98537
openssl-debuginfo-1.0.2k-26.el7_9.1.s390.rpm SHA-256: 7c5445ad023efb4b347597a39de60b88f1f213a958fe330d51724ec05e5af0ef
openssl-debuginfo-1.0.2k-26.el7_9.1.s390.rpm SHA-256: 7c5445ad023efb4b347597a39de60b88f1f213a958fe330d51724ec05e5af0ef
openssl-debuginfo-1.0.2k-26.el7_9.1.s390x.rpm SHA-256: acec6c387939300763b980abf14363c5d7fcb878127034e04d4475bb9e24f30d
openssl-debuginfo-1.0.2k-26.el7_9.1.s390x.rpm SHA-256: acec6c387939300763b980abf14363c5d7fcb878127034e04d4475bb9e24f30d
openssl-devel-1.0.2k-26.el7_9.1.s390.rpm SHA-256: f8e979fdcaf69aac41b0d8bba7dd1958e27ec883f271963c43717247f29a9fe4
openssl-devel-1.0.2k-26.el7_9.1.s390x.rpm SHA-256: c393a48572dd880415470b71a36dd9317ca944ff7ebd370372665b4ba775c851
openssl-libs-1.0.2k-26.el7_9.1.s390.rpm SHA-256: 70e66bc2bb7392842e8d3f0bc50444f97909e09af2c1c4a4fd735ea6e713c5c7
openssl-libs-1.0.2k-26.el7_9.1.s390x.rpm SHA-256: c5903d177bfcc09024b96cb2bba941de471d20d89970faedd5f51972e5852511
openssl-perl-1.0.2k-26.el7_9.1.s390x.rpm SHA-256: 19efa782773c3838e5575e282d11298b5e6c83b4e8c55773a5b16e093012f164
openssl-static-1.0.2k-26.el7_9.1.s390.rpm SHA-256: cb7e3dc5baf058cb80e291f7bfd58adf85210bb678fc41f9ebe36f078e726043
openssl-static-1.0.2k-26.el7_9.1.s390x.rpm SHA-256: 53fa2bfcfcf51c41f93a54ed9ee359184792be4d8467d6e667977d8358cc501b

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
openssl-1.0.2k-26.el7_9.1.src.rpm SHA-256: e91340c5594a2a613a032cfa9e75ecb258905384b24dc60ff021ba4c1b3746c5
ppc64
openssl-1.0.2k-26.el7_9.1.ppc64.rpm SHA-256: 1debff6c8849be170198184f7e4b72afa7361ce610da333966568a497579b298
openssl-debuginfo-1.0.2k-26.el7_9.1.ppc.rpm SHA-256: fd6db7133e128f99a0fe6cc5be71bede9b013a5bdac9c756e679930cf51f47bc
openssl-debuginfo-1.0.2k-26.el7_9.1.ppc.rpm SHA-256: fd6db7133e128f99a0fe6cc5be71bede9b013a5bdac9c756e679930cf51f47bc
openssl-debuginfo-1.0.2k-26.el7_9.1.ppc64.rpm SHA-256: 68d3b2e29e618ac915f9f3c147859b9614a6eb0c76be2216837bdb6dd85665f2
openssl-debuginfo-1.0.2k-26.el7_9.1.ppc64.rpm SHA-256: 68d3b2e29e618ac915f9f3c147859b9614a6eb0c76be2216837bdb6dd85665f2
openssl-devel-1.0.2k-26.el7_9.1.ppc.rpm SHA-256: 95a8941a523476f26f69f52ea9332ae461b1a6ffc371ba9f3a648a5c8b2d5c89
openssl-devel-1.0.2k-26.el7_9.1.ppc64.rpm SHA-256: bedb298d02b3e27e444799d07f9461b70654de6bdd2701b21b37f5882acef556
openssl-libs-1.0.2k-26.el7_9.1.ppc.rpm SHA-256: 32b13790e72ff57491dc8f1a75eb0152fa53d5e45ca0b227eaddf82acf3d7e97
openssl-libs-1.0.2k-26.el7_9.1.ppc64.rpm SHA-256: 7c6780974cd70973ed132f5fae2657e2a5b9e121fb2f2a006c6774dff32da9ea
openssl-perl-1.0.2k-26.el7_9.1.ppc64.rpm SHA-256: ae9483e5576fccfb603581771e0e7802db205b3cb75f46ca4a51460377c3b004
openssl-static-1.0.2k-26.el7_9.1.ppc.rpm SHA-256: 46c9269a9c39e17009fba6035dd3725b35ca8244f3d569cdc96fe45885e2e285
openssl-static-1.0.2k-26.el7_9.1.ppc64.rpm SHA-256: bbc6d1f57a09b1eb3abe86a98ba05c6fd268ea978aa99fd0d538acc3e5314643

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
openssl-1.0.2k-26.el7_9.1.src.rpm SHA-256: e91340c5594a2a613a032cfa9e75ecb258905384b24dc60ff021ba4c1b3746c5
ppc64le
openssl-1.0.2k-26.el7_9.1.ppc64le.rpm SHA-256: e7546a7182d8c5e3d37d6f3eea42df783f4cc194aef01dba7098b95ae56ae841
openssl-debuginfo-1.0.2k-26.el7_9.1.ppc64le.rpm SHA-256: ef810cfadfa562624d94f6136cc1bee32d8591b8feca8c043ab54402650611bc
openssl-debuginfo-1.0.2k-26.el7_9.1.ppc64le.rpm SHA-256: ef810cfadfa562624d94f6136cc1bee32d8591b8feca8c043ab54402650611bc
openssl-devel-1.0.2k-26.el7_9.1.ppc64le.rpm SHA-256: f022e48642e82d201dd50d65e52fc6c58301bd0c3ac9e144e756b4464e129cda
openssl-libs-1.0.2k-26.el7_9.1.ppc64le.rpm SHA-256: c5779faca9ddca97fbf9a1f35b59e7d3cc9bbf8463d4f40fbd505ff75102fc0e
openssl-perl-1.0.2k-26.el7_9.1.ppc64le.rpm SHA-256: 504c146fe50ef8a61904bc5eca915a0f78190c62a0a5c04aa142803fef88e808
openssl-static-1.0.2k-26.el7_9.1.ppc64le.rpm SHA-256: e3e699a9ff5f134d1e8b0a095eb366092d7765a71cd4701246056d32e1bec306

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility