Bug 2447397

Summary: CVE-2026-2673 openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group [fedora-all]
Product: [Fedora] Fedora Reporter: Jon Moroney <jmoroney>
Component: opensslAssignee: Dmitry Belyavskiy <dbelyavs>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: low    
Version: rawhideCC: awilliam, crypto-team, dbelyavs, mspacek, mturk, pzacik, robatino, shebburn, suraj.ghimire7, tm
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---Flags: fedora-admin-xmlrpc: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["0d4ab7b1-87de-4428-890e-bc48ea86132f"]}
Fixed In Version: openssl-3.5.5-2.fc44 openssl-3.5.4-3.fc43 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-04-22 11:13:38 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2447327, 2362359    

Description Jon Moroney 2026-03-13 18:29:51 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Fedora Update System 2026-04-21 08:53:50 UTC
FEDORA-2026-47fffff581 (openssl-3.5.4-3.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-47fffff581

Comment 2 Pavol Zacik 2026-04-21 08:55:35 UTC
*** Bug 2447399 has been marked as a duplicate of this bug. ***

Comment 3 Fedora Update System 2026-04-21 08:56:32 UTC
FEDORA-2026-d3e275d525 (openssl-3.5.5-2.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d3e275d525

Comment 4 Fedora Blocker Bugs Application 2026-04-22 09:28:00 UTC
Proposed as a Blocker for 44-final by Fedora user pbrobinson using the blocker tracking app because:

 Criterion: "The release must contain no known security bugs of 'important' or higher impact according to the Red Hat severity classification scale which cannot be satisfactorily resolved by a package update (e.g. issues during installation)."

* CVE-2026-2673 - opencve: high - redhat: low 	  
* CVE-2026-28387 - opencve: low - redhat:  low
* CVE-2026-28388 - opencve: high - redhat:  low
* CVE-2026-28389 - opencve: high - redhat:  low
* CVE-2026-28390 - opencve: high - redhat:  moderate
* CVE-2026-31789 - opencve: medium - redhat:  low
* CVE-2026-31790 - opencve: high - redhat:  moderate

Openssl ships on all Fedora artifacts.

Comment 5 Dmitry Belyavskiy 2026-04-22 11:13:38 UTC
This issue is irrelevant for Fedora, we rely on crypto-policies configuring TLS properties, and don't rely on 'DEFAULT' keyword.

Comment 6 Adam Williamson 2026-04-22 15:57:33 UTC
I believe Peter was proposing this as a proxy for *all* of the CVEs he listed, Dmitry. Are any of those concerning for Fedora?

Comment 7 Dmitry Belyavskiy 2026-04-22 17:36:36 UTC
I think yes, the remaining should be fixed in F44. Pavol Zacik, could you please confirm?

Comment 8 Dmitry Belyavskiy 2026-04-22 18:50:27 UTC
I think yes, the remaining should be fixed in F44. Pavol Zacik, could you please confirm?

Comment 9 Adam Williamson 2026-04-22 18:54:35 UTC
For blocker status, key question is whether any of them rate 'important' on RH's scale.

Comment 10 Fedora Update System 2026-04-23 01:34:26 UTC
FEDORA-2026-d3e275d525 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-d3e275d525`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-d3e275d525

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 Fedora Update System 2026-04-23 02:00:06 UTC
FEDORA-2026-47fffff581 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-47fffff581`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-47fffff581

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 12 Pavol Zacik 2026-04-23 06:29:14 UTC
Adam: All are rated either as low or moderate by Red Hat Product Security, so the blocker is not appropriate.

Dima: Yes, the build with all CVE patches is in testing and will be shipped after un-freeze.

Comment 13 Adam Williamson 2026-04-23 18:40:26 UTC
For the record, we didn't *formally* consider this one at the Go/No-Go blocker review as it was closed so it didn't show up in the list, but I did bring it up informally and it was clearly rejected, with 7 -1 votes.

Comment 14 Fedora Update System 2026-04-25 01:49:20 UTC
FEDORA-2026-d3e275d525 (openssl-3.5.5-2.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 15 Fedora Update System 2026-04-28 00:59:20 UTC
FEDORA-2026-47fffff581 (openssl-3.5.4-3.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.