OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.
Security Fix(es):
openssl: Unbounded memory growth with session handling in TLSv1.3 (CVE-2024-2511)
openssl: Excessive time spent checking DSA keys and parameters (CVE-2024-4603)
openssl: Use After Free with SSLfreebuffers (CVE-2024-4741)
openssl: SSLselectnext_proto buffer overread (CVE-2024-5535)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 9.5 Release Notes linked from the References section.