Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:7877 - Security Advisory
Issued:
2023-12-18
Updated:
2023-12-18

RHSA-2023:7877 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Low: openssl security update

Type/Severity

Security Advisory: Low

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openssl is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Security Fix(es):

  • openssl: Excessive time spent checking DH keys and parameters (CVE-2023-3446)
  • OpenSSL: Excessive time spent checking DH q parameter value (CVE-2023-3817)
  • openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow (CVE-2023-5678)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted.

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2224962 - CVE-2023-3446 openssl: Excessive time spent checking DH keys and parameters
  • BZ - 2227852 - CVE-2023-3817 OpenSSL: Excessive time spent checking DH q parameter value
  • BZ - 2248616 - CVE-2023-5678 openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow

CVEs

  • CVE-2023-3446
  • CVE-2023-3817
  • CVE-2023-5678
  • CVE-2024-2408

References

  • https://access.redhat.com/security/updates/classification/#low
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
openssl-1.1.1k-12.el8_9.src.rpm SHA-256: dc072a144f8e63b314f20f3ef95f9d371f51dcf31417449831adeedd48f86020
x86_64
openssl-1.1.1k-12.el8_9.x86_64.rpm SHA-256: b3ebcd7861e92e2970e59a8db2b28c92532ae8bb9d8dbf31c5f07fca18d949f1
openssl-debuginfo-1.1.1k-12.el8_9.i686.rpm SHA-256: a5f761dd17fd564ffae7e47d5aa1715e483ffea2bcb24e4d6ce4bc6927680cd4
openssl-debuginfo-1.1.1k-12.el8_9.x86_64.rpm SHA-256: 2ffafe8ddd0a52b200af106c3b49bc7b6f94720eb7e571be553c770845fdd492
openssl-debugsource-1.1.1k-12.el8_9.i686.rpm SHA-256: 7e53bacbef62064ff7f1e4fb703c88aaabe8c4e3052210bdfd6b605a0ca2be6e
openssl-debugsource-1.1.1k-12.el8_9.x86_64.rpm SHA-256: 8b5107cbc7926cf404a6c9c795f86be9573d04a84118c46e7af12ed2ab336c52
openssl-devel-1.1.1k-12.el8_9.i686.rpm SHA-256: e27d0089492fcc105c31f3162d84e0975866b78af0c4e87d894b7038f5750269
openssl-devel-1.1.1k-12.el8_9.x86_64.rpm SHA-256: e2e9458cff5023a30e1f60789fe40fcb30f777a3f46cf9635f00c1ca4b937c4f
openssl-libs-1.1.1k-12.el8_9.i686.rpm SHA-256: 29e075e8abf864aae6c2e64c7effeb0dfa14c998065ccbc226e2a823b4434dc9
openssl-libs-1.1.1k-12.el8_9.x86_64.rpm SHA-256: d1922c4b25187263adc3b05f881ca91cb10c1d332aa22b8df56dfb866112d750
openssl-libs-debuginfo-1.1.1k-12.el8_9.i686.rpm SHA-256: e5aafd15ccc5a6b2c6090b9be3b63831e9ed5159cff05babb187aee0098d7fc4
openssl-libs-debuginfo-1.1.1k-12.el8_9.x86_64.rpm SHA-256: 42dc603e1ba5e4df7bcea55ab6e8f04da1f16de7d917bf0bf2e09caf9796e8e5
openssl-perl-1.1.1k-12.el8_9.x86_64.rpm SHA-256: 54d3134105bc18a587737a5c6a319b0188e25b1121684dbde71ed55b4d5b6e93

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
openssl-1.1.1k-12.el8_9.src.rpm SHA-256: dc072a144f8e63b314f20f3ef95f9d371f51dcf31417449831adeedd48f86020
s390x
openssl-1.1.1k-12.el8_9.s390x.rpm SHA-256: de1ba77d0e508528818581e94cc53324e18b9931dd6c0b68d94bfbd54fb3583d
openssl-debuginfo-1.1.1k-12.el8_9.s390x.rpm SHA-256: d7db45f4fe25bec75b43bda0d55e0bd0210c6fcf50026041abb307564dee3b24
openssl-debugsource-1.1.1k-12.el8_9.s390x.rpm SHA-256: e2a555f0cb050f90fb07ca8a7976fcf09c3831b687a2bcdd2db9f3ee298bf0ef
openssl-devel-1.1.1k-12.el8_9.s390x.rpm SHA-256: 359989e5ede89d2f8f87faccc0b9411293bf13adbce4bbd66af4c8fb9d28cf2d
openssl-libs-1.1.1k-12.el8_9.s390x.rpm SHA-256: 0a2d532374d6f5ff3cfb1dcfb10b69061881d0859e949f300176432cbe523c79
openssl-libs-debuginfo-1.1.1k-12.el8_9.s390x.rpm SHA-256: d131c05b5b227773abe174dcf2858e1e39a784b2df4e66875c437b305dd82096
openssl-perl-1.1.1k-12.el8_9.s390x.rpm SHA-256: 40a79ea46e29adfa7c55e1f712894fa70fcb7f29bddd4c64c2f70bc27cf1764a

Red Hat Enterprise Linux for Power, little endian 8

SRPM
openssl-1.1.1k-12.el8_9.src.rpm SHA-256: dc072a144f8e63b314f20f3ef95f9d371f51dcf31417449831adeedd48f86020
ppc64le
openssl-1.1.1k-12.el8_9.ppc64le.rpm SHA-256: 88976a1aeafd107b50d0a7c19317f499a5bdef153844f19afc3f4be0a5f5e4b1
openssl-debuginfo-1.1.1k-12.el8_9.ppc64le.rpm SHA-256: 0254e54ade62dc46a8d243d686eece37475cabb95a96751fff8c76b27c7b410c
openssl-debugsource-1.1.1k-12.el8_9.ppc64le.rpm SHA-256: c2ad5da1884402f51a30d9611eaa83e011c194e34033c27ccf235ce19485b713
openssl-devel-1.1.1k-12.el8_9.ppc64le.rpm SHA-256: b9e00cd2fd23dd56fc6418d814aaae0b3b6434a7d2780b9d3aa0227e45013176
openssl-libs-1.1.1k-12.el8_9.ppc64le.rpm SHA-256: 79f271b57a4f962850213b0e5dc9b9ddb4c64c82264690c8c4f2e9e6daf39489
openssl-libs-debuginfo-1.1.1k-12.el8_9.ppc64le.rpm SHA-256: 1b43672aaae83db2dca6548af1487148626cabccb143bb98ea11680ad56feb29
openssl-perl-1.1.1k-12.el8_9.ppc64le.rpm SHA-256: 96aa4824ce58077a9fd821e480f61696f3f874cfe539459403881f2e7b446cbb

Red Hat Enterprise Linux for ARM 64 8

SRPM
openssl-1.1.1k-12.el8_9.src.rpm SHA-256: dc072a144f8e63b314f20f3ef95f9d371f51dcf31417449831adeedd48f86020
aarch64
openssl-1.1.1k-12.el8_9.aarch64.rpm SHA-256: 0fc85904be25bedbd131b568c3f34261d116df1d0ab91edf1c0374cb3f739388
openssl-debuginfo-1.1.1k-12.el8_9.aarch64.rpm SHA-256: 647333c7668a3ca76ceeea68cf01560e08e56c800e1079c750d881cead08dfc1
openssl-debugsource-1.1.1k-12.el8_9.aarch64.rpm SHA-256: b8b4b9747e802ed66db2d537b2b75bc87542c2a8078dff709cd195ad9f678b42
openssl-devel-1.1.1k-12.el8_9.aarch64.rpm SHA-256: a2fa149bef1847885da9cfb2511822c8a6028914ae209a05cd5c27715ae3d1e6
openssl-libs-1.1.1k-12.el8_9.aarch64.rpm SHA-256: eda2cddfd176e06ebfde396e81d47c84accc213d982543a3ad9fd6038bd763c3
openssl-libs-debuginfo-1.1.1k-12.el8_9.aarch64.rpm SHA-256: b09ab8e07c7cb9c1023aee961a82d1d800bfd0899b9cf81d7c086c4728fdf3bc
openssl-perl-1.1.1k-12.el8_9.aarch64.rpm SHA-256: 57ee9333c5c4e67b309df195035e53b7352eeb4a60086bd72aa2688b0e14b115

The Red Hat security contact is [email protected]. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility