Home / mailingsPDF  

[slackware-security] openssl (SSA:2026-101-01)

Posted on 12 April 2026
Slackware Security

[slackware-security] openssl (SSA:2026-101-01)

New openssl packages are available for Slackware 15.0 and -current to
fix security issues.


Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/openssl-1.1.1zg-i586-1_slack15.0.txz: Upgraded.
Apply patch to fix the following security issues:
Potential Use-after-free in DANE Client Code.
NULL Pointer Dereference When Processing a Delta CRL.
Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo.
Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo.
These CVEs were fixed by the 1.1.1zg release that is only available to
subscribers to OpenSSL's premium extended support. The patch was prepared
by backporting from the OpenSSL-3.0 repo.
Thanks to Ken Zalewski for the patch!
For more information, see:
https://openssl-library.org/news/vulnerabilities/#CVE-2026-28387
https://openssl-library.org/news/vulnerabilities/#CVE-2026-28388
https://openssl-library.org/news/vulnerabilities/#CVE-2026-28389
https://openssl-library.org/news/vulnerabilities/#CVE-2026-28390
https://www.cve.org/CVERecord?id=CVE-2026-28387
https://www.cve.org/CVERecord?id=CVE-2026-28388
https://www.cve.org/CVERecord?id=CVE-2026-28389
https://www.cve.org/CVERecord?id=CVE-2026-28390
(* Security fix *)
patches/packages/openssl-solibs-1.1.1zg-i586-1_slack15.0.txz: Upgraded.
+--------------------------+


Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated packages for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/openssl-1.1.1zg-i586-1_slack15.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/openssl-solibs-1.1.1zg-i586-1_slack15.0.txz

Updated packages for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/openssl-1.1.1zg-x86_64-1_slack15.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/openssl-solibs-1.1.1zg-x86_64-1_slack15.0.txz

Updated packages for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/openssl-solibs-3.5.6-i686-2.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/openssl-3.5.6-i686-2.txz

Updated packages for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/a/openssl-solibs-3.5.6-x86_64-2.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/openssl-3.5.6-x86_64-2.txz


MD5 signatures:
+-------------+

Slackware 15.0 packages:
210e557886d312155921afc0d1489c1e openssl-1.1.1zg-i586-1_slack15.0.txz
48a1ab14b7f68b36a9c63c5ff5c3d213 openssl-solibs-1.1.1zg-i586-1_slack15.0.txz

Slackware x86_64 15.0 packages:
c0252b08ac12a37c5b691006ba8bc9a0 openssl-1.1.1zg-x86_64-1_slack15.0.txz
2cb2a11d40ca6e005bbd5072fdbba694 openssl-solibs-1.1.1zg-x86_64-1_slack15.0.txz

Slackware -current packages:
95ba59895b0e518ebd1c751736cae5dc a/openssl-solibs-3.5.6-i686-2.txz
0cc9bb77cb0a278bd64ab748a81070ac n/openssl-3.5.6-i686-2.txz

Slackware x86_64 -current packages:
7f6dec19a4014269d928857ea4585f60 a/openssl-solibs-3.5.6-x86_64-2.txz
3ec248b78a6ea77d4776f0ed126874d8 n/openssl-3.5.6-x86_64-2.txz


Installation instructions:
+------------------------+

Upgrade the packages as root:
# upgradepkg openssl-1.1.1zg-i586-1_slack15.0.txz openssl-solibs-1.1.1zg-i586-1_slack15.0.txz


+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

 

TOP