OpenSSL has issued an advisory on December 13: https://www.openssl.org/news/secadv/20221213.txt The issue is fixed upstream in 3.0.8.
openSUSE has issued an advisory for this on December 20: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DNJ36X7C7HDY23A7KUN4WU7VEMCY2HUV/
Status comment: (none) => Fixed upstream in 3.0.8
Different people commit this SRPM, so asigning the bug globally. CC'ing NicolasS who has done several CVEs previously.
CC: (none) => nicolas.salgueroAssignee: bugsquad => pkg-bugs
Hi, openssl-3.0.5-4.mga9 includes the patch from openSUSE. Best regards, Nico.
Thanks. Any chance we can get 3.0.8 to build?
Resolution: (none) => FIXEDStatus: NEW => RESOLVED
Sadly, for the moment, version 3.0.8 is not released.