VDB

RHSA-2022%3A7384

RHSA-2022%3A7384 PUBLISHED CVSS 7.5 HIGH

A stack-based buffer overflow was found in the way OpenSSL processes X.509 certificates with a specially crafted email address field. This issue could cause a server or a client application compiled with OpenSSL to crash when trying to process the malicious certificate.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhel9/openssl@sha256:17d66d6147a8ced8665797de2e909ebd98e4ce7c1db9d42e693e88599c5718a4_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 9)*
Red Hatrhel9/openssl@sha256:3c32d03ba29856387d8f238bd2e17c8dc77a04af509df5664fe6c412ebb15347_ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)rhel9/openssl@sha256:3c32d03ba29856387d8f238bd2e17c8dc77a04af509df5664fe6c412ebb15347_ppc64le
Red Hatubi9/openssl@sha256:3c32d03ba29856387d8f238bd2e17c8dc77a04af509df5664fe6c412ebb15347_ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)*
Red Hatrhel9/openssl@sha256:a33b64e64982f6b9a876ef228abf1b76f553837a46747251cdea4c7576946050_s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)rhel9/openssl@sha256:a33b64e64982f6b9a876ef228abf1b76f553837a46747251cdea4c7576946050_s390x
Red Hatrhel9/openssl@sha256:a2af1c9744ae5c382121b446efcd673abb67e9fe017f35b06295628dd69c937c_arm64 as a component of Red Hat Enterprise Linux AppStream (v. 9)rhel9/openssl@sha256:a2af1c9744ae5c382121b446efcd673abb67e9fe017f35b06295628dd69c937c_arm64
Red Hatubi9/openssl@sha256:17d66d6147a8ced8665797de2e909ebd98e4ce7c1db9d42e693e88599c5718a4_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 9)ubi9/openssl@sha256:17d66d6147a8ced8665797de2e909ebd98e4ce7c1db9d42e693e88599c5718a4_amd64
Red Hatubi9/openssl@sha256:a2af1c9744ae5c382121b446efcd673abb67e9fe017f35b06295628dd69c937c_arm64 as a component of Red Hat Enterprise Linux AppStream (v. 9)*
Red Hatubi9/openssl@sha256:a33b64e64982f6b9a876ef228abf1b76f553837a46747251cdea4c7576946050_s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)ubi9/openssl@sha256:a33b64e64982f6b9a876ef228abf1b76f553837a46747251cdea4c7576946050_s390x

Timeline

  • Nov 2, 2022 CVE Published
  • Apr 14, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›