This update for openssl-1_1 fixes the following issues:
CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with
KeyTransportRecipientInfo (bsc#1261678).
Affected Packages
libopenssl-1_1-devel
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSSUSE Linux Enterprise High Performance Computing 15 SP5-LTSSSUSE Linux Enterprise Micro 5.5SUSE Linux Enterprise Server 15 SP5-LTSSSUSE Linux Enterprise Server for SAP Applications 15 SP5
Fixed in:
1.1.1l-150500.17.54.1
libopenssl1_1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSSUSE Linux Enterprise High Performance Computing 15 SP5-LTSSSUSE Linux Enterprise Micro 5.5SUSE Linux Enterprise Server 15 SP5-LTSSSUSE Linux Enterprise Server for SAP Applications 15 SP5
Fixed in:
1.1.1l-150500.17.54.1
libopenssl1_1-32bit
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSSUSE Linux Enterprise High Performance Computing 15 SP5-LTSSSUSE Linux Enterprise Server 15 SP5-LTSSSUSE Linux Enterprise Server for SAP Applications 15 SP5
Fixed in:
1.1.1l-150500.17.54.1
libopenssl1_1-hmac
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSSUSE Linux Enterprise High Performance Computing 15 SP5-LTSSSUSE Linux Enterprise Micro 5.5SUSE Linux Enterprise Server 15 SP5-LTSSSUSE Linux Enterprise Server for SAP Applications 15 SP5
Fixed in:
1.1.1l-150500.17.54.1
libopenssl1_1-hmac-32bit
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSSUSE Linux Enterprise High Performance Computing 15 SP5-LTSSSUSE Linux Enterprise Server 15 SP5-LTSSSUSE Linux Enterprise Server for SAP Applications 15 SP5
Fixed in:
1.1.1l-150500.17.54.1
openssl-1_1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSSUSE Linux Enterprise High Performance Computing 15 SP5-LTSSSUSE Linux Enterprise Micro 5.5SUSE Linux Enterprise Server 15 SP5-LTSSSUSE Linux Enterprise Server for SAP Applications 15 SP5