RedHat has issued an advisory on November 19: https://rhn.redhat.com/errata/RHSA-2015-2131.html The RedHat bug has an attached suggested patch: https://bugzilla.redhat.com/show_bug.cgi?id=1238322 but the patch they actually used is more significant: https://git.centos.org/blob/rpms!openldap.git/d198f9801b5096fcc16c36bd38621cae9f184ecd/SOURCES!openldap-nss-ciphersuite-handle-masks-correctly.patch Other patches they added in this update may be of interest too: https://git.centos.org/commit/rpms!openldap.git/refs!heads!c7 Mageia 5 is also affected. Reproducible: Steps to Reproduce:
These issues come from their using the NSS implementation for TLS. We use the OpenSSL implementation, so this doesn't affect us.
Status: NEW => RESOLVEDResolution: (none) => INVALID