{
  "cves": [
    "CVE-2024-4741",
    "CVE-2026-45447"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1:1.1.1k-16]\n- Fix CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify()\n  Resolves: RHEL-180978\n- Fix CVE-2024-4741: Use After Free with SSL_free_buffers\n  Resolves: RHEL-180983\n\n[1:1.1.1k-15]\n- Fix CVE-2025-69419: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing\n  ticket_lifetime_hint exceed 1 week in TLSv1.3 and breaks compliant clients\n  Resolves: RHEL-149165\n  Resolves: RHEL-142715\n\n[1:1.1.1k-14.1]\n- Backport fix for openssl: Out-of-bounds read  write in RFC 3211 KEK Unwrap\n  Fix CVE-2025-9230\n  Resolves: RHEL-128615\n\n[1:1.1.1k-14]\n- Backport fix SSL_select_next proto from OpenSSL 3.2\n  Fix CVE-2024-5535\n  Resolves: RHEL-45654",
  "id": "ELSA-2026-50323",
  "ovalId": "oval:com.oracle.elsa:def:202650323",
  "source": "oracle_linux",
  "title": "ELSA-2026-50323: openssl security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-50323.html"
}