OpenSSL has issued an advisory on April 20: https://www.openssl.org/news/secadv/20230420.txt Only 3.x is affected (Cauldron) and only on ARM. The next OpenSSL version will contain the fix.
ns80 is the main committer of openssl, so assigning this to you. Is it worth waiting?
Summary: openssl new security issue CVE-2023-1255 => openssl new security issue CVE-2023-1255, only for v3.x on ArmAssignee: bugsquad => nicolas.salguero
Hi, openssl-3.0.8-3.mga9 already contains the fix for that CVE. Best regards, Nico.
Thanks.
Status: NEW => RESOLVEDResolution: (none) => FIXED