Vulnerabilities in OpenSSL < 3.5.6 and < 3.6.2

Hi,

I’m looking for information about the release of fixed OpenSSL versions that address the recently revealed CVEs (for example CVE-2026-31790):

https://openssl-library.org/news/secadv/20260407.txt

Does anyone know when openssl-3.5.6 or openssl-3.6.2 will be available in the repositories?

The new version was released 2 days ago on Github:

CVE Guide
The above guide describes how to find out if a CVE is patched and where to look to find out if and when. Since rocky is dependent on RH timeline to fix you need to start there. Each OS may have a different timeline, 8, 9 or 10. Rocky will put any RH update in their build que once issued by RH and the RL build may take days or week before RL issue.

Is there any news on this?

Did you check to see if Red Hat fixed it? Cos if they didn’t, then it won’t appear in Rocky until they do.