{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/oraclelinux7els/vex/2026/cve-2026-22796-els_os-oraclelinux7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-02-10T14:39:45Z",
      "generator": {
        "date": "2026-02-10T14:39:45Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-22796-ELS_OS-ORACLELINUX7ELS",
      "initial_release_date": "2026-01-27T00:00:00Z",
      "revision_history": [
        {
          "date": "2026-01-27T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-02-10T14:39:45Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-22796"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Oracle Linux 7",
                "product": {
                  "name": "Oracle Linux 7",
                  "product_id": "Oracle-Linux-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Oracle Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/openssl@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-devel-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-devel-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/openssl-devel@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-libs-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-libs-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/openssl-libs@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-perl-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-perl-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/openssl-perl@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-static-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-static-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/openssl-static@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.0.2k-26.el7_9.i686",
                "product": {
                  "name": "openssl-devel-1:1.0.2k-26.el7_9.i686",
                  "product_id": "openssl-devel-1:1.0.2k-26.el7_9.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/openssl-devel@1.0.2k-26.el7_9?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.0.2k-26.el7_9.i686",
                "product": {
                  "name": "openssl-libs-1:1.0.2k-26.el7_9.i686",
                  "product_id": "openssl-libs-1:1.0.2k-26.el7_9.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/openssl-libs@1.0.2k-26.el7_9?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.0.2k-26.el7_9.i686",
                "product": {
                  "name": "openssl-static-1:1.0.2k-26.el7_9.i686",
                  "product_id": "openssl-static-1:1.0.2k-26.el7_9.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/openssl-static@1.0.2k-26.el7_9?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "Oracle Corporation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-perl@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-static@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                "product": {
                  "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_id": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.0.2k-26.el7_9.tuxcare.els6?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                "product": {
                  "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_id": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.0.2k-26.el7_9.tuxcare.els6?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                "product": {
                  "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_id": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-static@1.0.2k-26.el7_9.tuxcare.els6?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:1.0.2k-26.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686"
        },
        "product_reference": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.0.2k-26.el7_9.i686 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.i686"
        },
        "product_reference": "openssl-devel-1:1.0.2k-26.el7_9.i686",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.0.2k-26.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-devel-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686"
        },
        "product_reference": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.0.2k-26.el7_9.i686 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.i686"
        },
        "product_reference": "openssl-libs-1:1.0.2k-26.el7_9.i686",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.0.2k-26.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-libs-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:1.0.2k-26.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-perl-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-perl-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686"
        },
        "product_reference": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.0.2k-26.el7_9.i686 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.i686"
        },
        "product_reference": "openssl-static-1:1.0.2k-26.el7_9.i686",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.0.2k-26.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-static-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-22796",
      "cwe": {
        "id": "CWE-1287",
        "name": "Improper Validation of Specified Type of Input"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Oracle-Linux-7:openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Oracle-Linux-7:openssl-1:1.0.2k-26.el7_9.x86_64",
          "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.i686",
          "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
          "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.x86_64",
          "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.i686",
          "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
          "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.x86_64",
          "Oracle-Linux-7:openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Oracle-Linux-7:openssl-perl-1:1.0.2k-26.el7_9.x86_64",
          "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.i686",
          "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
          "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-22796"
        }
      ],
      "release_date": "2026-01-27T00:00:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "This is a denial‑of‑service–only bug in OpenSSL’s legacy PKCS#7 verification path and requires a specially crafted signed PKCS#7 object to reach code that actually calls PKCS7_digest_from_attributes; common OpenSSL usages such as TLS handshakes do not invoke PKCS#7 parsing. Because there is no confidentiality or integrity impact and exploitation hinges on an application accepting untrusted PKCS#7 input, the practical risk to centrally managed server/VM workloads is low. Additionally, the FIPS modules are not affected, which further limits exposure in FIPS‑constrained deployments.",
          "product_ids": [
            "Oracle-Linux-7:openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-1:1.0.2k-26.el7_9.x86_64",
            "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.i686",
            "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.x86_64",
            "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.i686",
            "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.x86_64",
            "Oracle-Linux-7:openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-perl-1:1.0.2k-26.el7_9.x86_64",
            "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.i686",
            "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-1:1.0.2k-26.el7_9.x86_64",
            "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.i686",
            "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-devel-1:1.0.2k-26.el7_9.x86_64",
            "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.i686",
            "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-libs-1:1.0.2k-26.el7_9.x86_64",
            "Oracle-Linux-7:openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-perl-1:1.0.2k-26.el7_9.x86_64",
            "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.i686",
            "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Oracle-Linux-7:openssl-static-1:1.0.2k-26.el7_9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}