{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2025/cve-2025-15468-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-02-10T15:03:41Z",
      "generator": {
        "date": "2026-02-10T15:03:41Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-15468-ELS_OS-RHEL7ELS",
      "initial_release_date": "2025-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2025-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-02-10T15:03:41Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-15468"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-devel-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-devel-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-libs-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-libs-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-perl-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-perl-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-perl@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.0.2k-26.el7_9.x86_64",
                "product": {
                  "name": "openssl-static-1:1.0.2k-26.el7_9.x86_64",
                  "product_id": "openssl-static-1:1.0.2k-26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-static@1.0.2k-26.el7_9?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.0.2k-26.el7_9.i686",
                "product": {
                  "name": "openssl-devel-1:1.0.2k-26.el7_9.i686",
                  "product_id": "openssl-devel-1:1.0.2k-26.el7_9.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@1.0.2k-26.el7_9?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.0.2k-26.el7_9.i686",
                "product": {
                  "name": "openssl-libs-1:1.0.2k-26.el7_9.i686",
                  "product_id": "openssl-libs-1:1.0.2k-26.el7_9.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@1.0.2k-26.el7_9?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.0.2k-26.el7_9.i686",
                "product": {
                  "name": "openssl-static-1:1.0.2k-26.el7_9.i686",
                  "product_id": "openssl-static-1:1.0.2k-26.el7_9.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-static@1.0.2k-26.el7_9?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-perl@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_id": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-static@1.0.2k-26.el7_9.tuxcare.els6?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                "product": {
                  "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_id": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.0.2k-26.el7_9.tuxcare.els6?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                "product": {
                  "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_id": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.0.2k-26.el7_9.tuxcare.els6?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                "product": {
                  "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_id": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-static@1.0.2k-26.el7_9.tuxcare.els6?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:1.0.2k-26.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686"
        },
        "product_reference": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.0.2k-26.el7_9.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.i686"
        },
        "product_reference": "openssl-devel-1:1.0.2k-26.el7_9.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.0.2k-26.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-devel-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686"
        },
        "product_reference": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.0.2k-26.el7_9.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.i686"
        },
        "product_reference": "openssl-libs-1:1.0.2k-26.el7_9.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.0.2k-26.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-libs-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:1.0.2k-26.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-perl-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-perl-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686"
        },
        "product_reference": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.0.2k-26.el7_9.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.i686"
        },
        "product_reference": "openssl-static-1:1.0.2k-26.el7_9.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.0.2k-26.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.x86_64"
        },
        "product_reference": "openssl-static-1:1.0.2k-26.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-15468",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: If an application using the SSL_CIPHER_find() function in\na QUIC protocol client or server receives an unknown cipher suite from\nthe peer, a NULL dereference occurs.\nImpact summary: A NULL pointer dereference leads to abnormal termination of\nthe running process causing Denial of Service.\nSome applications call SSL_CIPHER_find() from the client_hello_cb callback\non the cipher ID received from the peer. If this is done with an SSL object\nimplementing the QUIC protocol, NULL pointer dereference will happen if\nthe examined cipher ID is unknown or unsupported.\nAs it is not very common to call this function in applications using the QUIC \nprotocol and the worst outcome is Denial of Service, the issue was assessed\nas Low severity.\nThe vulnerable code was introduced in the 3.2 version with the addition\nof the QUIC protocol support.\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the QUIC implementation is outside the OpenSSL FIPS module boundary.\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:openssl-1:1.0.2k-26.el7_9.x86_64",
          "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.i686",
          "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
          "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.x86_64",
          "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.i686",
          "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
          "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.x86_64",
          "Red-Hat-7:openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:openssl-perl-1:1.0.2k-26.el7_9.x86_64",
          "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.i686",
          "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
          "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-15468"
        }
      ],
      "release_date": "2026-01-27T00:00:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "This flaw only triggers in QUIC code paths when an application explicitly calls SSL_CIPHER_find() from client_hello_cb on a peer-provided cipher ID—a non-default, application-specific pattern; standard TLS-over-TCP or QUIC usages that do not use this callback path are unaffected. The impact is limited to a process crash (availability only) with high attack complexity and no confidentiality or integrity risk, making practical exploitation low-value in server/VM environments. Exposure is further reduced because only OpenSSL 3.3–3.6 non-FIPS builds are affected; OpenSSL 3.0/1.1.1/1.0.2 and FIPS modules are not impacted.",
          "product_ids": [
            "Red-Hat-7:openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-1:1.0.2k-26.el7_9.x86_64",
            "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.i686",
            "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.x86_64",
            "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.i686",
            "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.x86_64",
            "Red-Hat-7:openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-perl-1:1.0.2k-26.el7_9.x86_64",
            "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.i686",
            "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red-Hat-7:openssl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-1:1.0.2k-26.el7_9.x86_64",
            "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.i686",
            "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-devel-1:1.0.2k-26.el7_9.x86_64",
            "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.i686",
            "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-libs-1:1.0.2k-26.el7_9.x86_64",
            "Red-Hat-7:openssl-perl-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-perl-1:1.0.2k-26.el7_9.x86_64",
            "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.i686",
            "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.i686",
            "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:openssl-static-1:1.0.2k-26.el7_9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}