Hello,
The openssl fix 46 have been published by IBM this 1à march afternoon.
Regards
Michel
Original Message:
Sent: 3/10/2026 5:09:00 PM
From: Sveinn Gunnarsson
Subject: RE: OpenSSL CVE-2025-15467
To be honest I wonder how a response time of 40 days can be justified for an OpenSSL CVE with a score of 9.8
Comparing this response with other OS vendors has me worried.
------------------------------
Sveinn Gunnarsson
------------------------------
Original Message:
Sent: Tue March 10, 2026 01:25 PM
From: Alexander Pettitt
Subject: OpenSSL CVE-2025-15467
I wonder if the hold up was IBM kept seeing more CVEs and restarting the development cycle without releasing. That will be something they have to watch in the future.
------------------------------
Alexander Pettitt
Original Message:
Sent: Tue March 10, 2026 01:19 PM
From: Sveinn Gunnarsson
Subject: OpenSSL CVE-2025-15467
Hi all.
Apparently openssl_fix46.tar has made available and it contains fix for CVE-2025-15467 and handful of lesser CVEs.
Cheers!
------------------------------
Sveinn Gunnarsson
Original Message:
Sent: Fri March 06, 2026 05:35 AM
From: Michel Oger
Subject: OpenSSL CVE-2025-15467
Hi Akanksha,
I'm also waiting for this ifix. I need to have an answer for the delivery date to comnicate that at my management
Regards
Michel Oger
------------------------------
Michel Oger
Original Message:
Sent: Mon February 02, 2026 01:01 AM
From: AKANKSHA PRIYA
Subject: OpenSSL CVE-2025-15467
Hi Sveinn,
CVE-2025-15467 impacts 3.0 OpenSSL version. Fix for the same will be delivered as ifix with prerequisite as openssl.base 3.0.16.1000 VRMF.
ETA : February 16th 2026
Thanks,
Akanksha Priya
------------------------------
AKANKSHA PRIYA
Original Message:
Sent: Sun February 01, 2026 08:41 AM
From: Sveinn Gunnarsson
Subject: OpenSSL CVE-2025-15467
Hi all.
My security team is asking me about this critical OpenSSL vulnerability CVE-2025-15467 and fix for AIX. Latest OpenSSL version available on AIX Web Download pack is 3.0.16 which does not address this vulnerability.
Is there an impact summary I can pass to them, or scheduled fix for OpenSSL?
Thank you in advance.
------------------------------
----------------------
Sveinn Gunnarsson
------------------------------