Bug 2447397 - CVE-2026-2673 openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group [fedora-all]
Summary: CVE-2026-2673 openssl: OpenSSL TLS 1.3 server may choose unexpected key agree...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: openssl
Version: rawhide
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Dmitry Belyavskiy
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["0d4ab7b1-87de-4428-890e-b...
: 2447399 (view as bug list)
Depends On:
Blocks: CVE-2026-2673 F44FinalBlocker
TreeView+ depends on / blocked
 
Reported: 2026-03-13 18:29 UTC by Jon Moroney
Modified: 2026-04-28 00:59 UTC (History)
10 users (show)

Fixed In Version: openssl-3.5.5-2.fc44 openssl-3.5.4-3.fc43
Clone Of:
Environment:
Last Closed: 2026-04-22 11:13:38 UTC
Type: ---
Embargoed:
fedora-admin-xmlrpc: mirror+


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FC-3344 0 None None None 2026-03-13 18:31:48 UTC

Description Jon Moroney 2026-03-13 18:29:51 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Fedora Update System 2026-04-21 08:53:50 UTC
FEDORA-2026-47fffff581 (openssl-3.5.4-3.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-47fffff581

Comment 2 Pavol Zacik 2026-04-21 08:55:35 UTC
*** Bug 2447399 has been marked as a duplicate of this bug. ***

Comment 3 Fedora Update System 2026-04-21 08:56:32 UTC
FEDORA-2026-d3e275d525 (openssl-3.5.5-2.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d3e275d525

Comment 4 Fedora Blocker Bugs Application 2026-04-22 09:28:00 UTC
Proposed as a Blocker for 44-final by Fedora user pbrobinson using the blocker tracking app because:

 Criterion: "The release must contain no known security bugs of 'important' or higher impact according to the Red Hat severity classification scale which cannot be satisfactorily resolved by a package update (e.g. issues during installation)."

* CVE-2026-2673 - opencve: high - redhat: low 	  
* CVE-2026-28387 - opencve: low - redhat:  low
* CVE-2026-28388 - opencve: high - redhat:  low
* CVE-2026-28389 - opencve: high - redhat:  low
* CVE-2026-28390 - opencve: high - redhat:  moderate
* CVE-2026-31789 - opencve: medium - redhat:  low
* CVE-2026-31790 - opencve: high - redhat:  moderate

Openssl ships on all Fedora artifacts.

Comment 5 Dmitry Belyavskiy 2026-04-22 11:13:38 UTC
This issue is irrelevant for Fedora, we rely on crypto-policies configuring TLS properties, and don't rely on 'DEFAULT' keyword.

Comment 6 Adam Williamson 2026-04-22 15:57:33 UTC
I believe Peter was proposing this as a proxy for *all* of the CVEs he listed, Dmitry. Are any of those concerning for Fedora?

Comment 7 Dmitry Belyavskiy 2026-04-22 17:36:36 UTC
I think yes, the remaining should be fixed in F44. Pavol Zacik, could you please confirm?

Comment 8 Dmitry Belyavskiy 2026-04-22 18:50:27 UTC
I think yes, the remaining should be fixed in F44. Pavol Zacik, could you please confirm?

Comment 9 Adam Williamson 2026-04-22 18:54:35 UTC
For blocker status, key question is whether any of them rate 'important' on RH's scale.

Comment 10 Fedora Update System 2026-04-23 01:34:26 UTC
FEDORA-2026-d3e275d525 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-d3e275d525`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-d3e275d525

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 Fedora Update System 2026-04-23 02:00:06 UTC
FEDORA-2026-47fffff581 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-47fffff581`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-47fffff581

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 12 Pavol Zacik 2026-04-23 06:29:14 UTC
Adam: All are rated either as low or moderate by Red Hat Product Security, so the blocker is not appropriate.

Dima: Yes, the build with all CVE patches is in testing and will be shipped after un-freeze.

Comment 13 Adam Williamson 2026-04-23 18:40:26 UTC
For the record, we didn't *formally* consider this one at the Go/No-Go blocker review as it was closed so it didn't show up in the list, but I did bring it up informally and it was clearly rejected, with 7 -1 votes.

Comment 14 Fedora Update System 2026-04-25 01:49:20 UTC
FEDORA-2026-d3e275d525 (openssl-3.5.5-2.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 15 Fedora Update System 2026-04-28 00:59:20 UTC
FEDORA-2026-47fffff581 (openssl-3.5.4-3.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.