AIX

AIX

Connect with fellow AIX users and experts to gain knowledge, share insights, and solve problems.


#Power
#Power
 View Only
  • 1.  OpenSSL CVE-2025-15467

    Posted Sun February 01, 2026 08:42 AM

    Hi all.

    My security team is asking me about this critical OpenSSL vulnerability CVE-2025-15467 and fix for AIX. Latest OpenSSL version available on AIX Web Download pack is 3.0.16 which does not address this vulnerability.

    Is there an impact summary I can pass to them, or scheduled fix for OpenSSL?

    Thank you in advance.



    ------------------------------
    ----------------------
    Sveinn Gunnarsson
    ------------------------------


  • 2.  RE: OpenSSL CVE-2025-15467

    Posted Mon February 02, 2026 01:02 AM

    Hi Sveinn,

    CVE-2025-15467 impacts 3.0 OpenSSL version. Fix for the same will be delivered as ifix with prerequisite as openssl.base 3.0.16.1000 VRMF.

    ETA : February 16th 2026

    Thanks,

    Akanksha Priya



    ------------------------------
    AKANKSHA PRIYA
    ------------------------------



  • 3.  RE: OpenSSL CVE-2025-15467

    Posted Wed March 04, 2026 08:21 AM

    Hi Akanksha,

    Is there a new ETA date?

    Thanks,
    Daniel



    ------------------------------
    Daniel Kern
    ------------------------------



  • 4.  RE: OpenSSL CVE-2025-15467

    Posted Fri March 06, 2026 08:33 AM

    Hi Akanksha,

    I'm also waiting for this ifix. I need to have an answer for the delivery date to comnicate that at my management

    Regards

    Michel Oger



    ------------------------------
    Michel Oger
    ------------------------------



  • 5.  RE: OpenSSL CVE-2025-15467

    Posted Tue March 10, 2026 01:19 PM

    Hi all.

    Apparently openssl_fix46.tar has made available and it contains fix for CVE-2025-15467 and handful of lesser CVEs.

    Cheers!



    ------------------------------
    Sveinn Gunnarsson
    ------------------------------



  • 6.  RE: OpenSSL CVE-2025-15467

    Posted Tue March 10, 2026 01:25 PM

    I wonder if the hold up was IBM kept seeing more CVEs and restarting the development cycle without releasing. That will be something they have to watch in the future.



    ------------------------------
    Alexander Pettitt
    ------------------------------



  • 7.  RE: OpenSSL CVE-2025-15467

    Posted Tue March 10, 2026 05:09 PM

    To be honest I wonder how a response time of 40 days can be justified for an OpenSSL CVE with a score of 9.8

    Comparing this response with other OS vendors has me worried.



    ------------------------------
    Sveinn Gunnarsson
    ------------------------------



  • 8.  RE: OpenSSL CVE-2025-15467

    Posted Fri March 13, 2026 05:15 AM
    Hello,

    The openssl fix 46 have been published by IBM this 1à march afternoon.

    Regards
    Michel





  • 9.  RE: OpenSSL CVE-2025-15467

    Posted Sun March 29, 2026 06:57 AM

    Hi 

    Check the below link for more details

    https://www.ibm.com/support/pages/node/7262978?myns=swgother&mynp=OCSWG10&mynp=OCSSPHKW&mync=E&cm_sp=swgother-_-OCSWG10-OCSSPHKW-_-E

    Thank you



    ------------------------------
    Anas AlSaleh
    IBM Power Systems Software Specialist
    Saudi Business Machines ( SBM )
    Riyadh
    ------------------------------