{"cves":["CVE-2024-4741","CVE-2026-45447"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[1:1.1.1k-16]\n- Fix CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify()\n  Resolves: RHEL-180978\n- Fix CVE-2024-4741: Use After Free with SSL_free_buffers\n  Resolves: RHEL-180983\n\n[1:1.1.1k-15]\n- Fix CVE-2025-69419: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing\n  ticket_lifetime_hint exceed 1 week in TLSv1.3 and breaks compliant clients\n  Resolves: RHEL-149165\n  Resolves: RHEL-142715\n\n[1:1.1.1k-14.1]\n- Backport fix for openssl: Out-of-bounds read  write in RFC 3211 KEK Unwrap\n  Fix CVE-2025-9230\n  Resolves: RHEL-128615\n\n[1:1.1.1k-14]\n- Backport fix SSL_select_next proto from OpenSSL 3.2\n  Fix CVE-2024-5535\n  Resolves: RHEL-45654","id":"ELSA-2026-50323","ovalId":"oval:com.oracle.elsa:def:202650323","source":"oracle_linux","title":"ELSA-2026-50323: openssl security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-50323.html"}