Resolution for CVE-2021-23839, CVE-2021-23840 and CVE-2021-23841
Issue
- What Red Hat products and distributed versions of OpenSSL are affected?
- openssl: incorrect SSLv2 rollback protection (CVE-2021-23839)
- openssl: integer overflow in CipherUpdate (CVE-2021-23840)
- openssl: NULL pointer dereference in X509_issuer_and_serial_hash (CVE-2021-23841)
Environment
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 6
- Red Hat OpenShift Container Platform 4.6
- Red Hat OpenShift Container Platform 4.5
- Red Hat OpenShift Container Platform 4.4
- Red Hat JBoss Enterprise Application Platform 6
- Red Hat Advanced Cluster Management for Kubernetes 2
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.