{"schema_version":"1.7.5","id":"SUSE-SU-2026:21544-1","published":"2026-05-05T00:19:27Z","modified":"2026-05-12T18:26:59.951341Z","related":["CVE-2025-11187","CVE-2025-15467","CVE-2025-15468","CVE-2025-9230"],"upstream":["CVE-2025-11187","CVE-2025-15467","CVE-2025-15468","CVE-2025-9230"],"summary":"Security update for openssl-3-x86_64-v3-livepatches","details":"This update for openssl-3-x86_64-v3-livepatches fixes the following issues:\n\nChanges in openssl-3-x86_64-v3-livepatches:\n\n- Add package for libopenssl3-x86-64-v3-3.5.0 (bsc#1259271).\n\nFixed:\n\n- CVE-2025-11187: Fixed Improper validation of PBMAC1 parameters in PKCS#12 MAC verification  (bsc#1256878).\n- CVE-2025-15467: Fixed Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876).\n- CVE-2025-15468: Fixed NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880).\n- CVE-2025-9230: Fixed Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230) (bsc#1250410).\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621544-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250410"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256876"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256880"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11187"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-15467"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-15468"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-9230"}]}