<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>Tuxcare Errata System</oval:product_name>
    <oval:product_version>0.0.1</oval:product_version>
    <oval:schema_version>5.10</oval:schema_version>
    <oval:timestamp>2026-09-18T08:33:47</oval:timestamp>
  </generator>
  <definitions>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1774531653" version="1">
      <metadata>
        <title>Update of alt-openssl11</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1774531653" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1774531653" source="CLSA"/>
        <reference ref_id="CVE-2026-22796" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-22796" source="CVE"/>
        <reference ref_id="CVE-2025-69421" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-69421" source="CVE"/>
        <description>- strip debug symbols from binary files</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-26"/>
          <updated date="2026-03-26"/>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1287" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-22796" impact="moderate" public="20260127">CVE-2026-22796</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-69421" impact="important" public="20260127">CVE-2025-69421</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 1:1.1.1w-3.1.el10" test_ref="oval:com.tuxcare.clsa:tst:1774531653001"/>
        <criterion comment="alt-openssl11 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653002"/>
        <criterion comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.1.el10" test_ref="oval:com.tuxcare.clsa:tst:1774531653003"/>
        <criterion comment="alt-openssl11-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653004"/>
        <criterion comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.1.el10" test_ref="oval:com.tuxcare.clsa:tst:1774531653005"/>
        <criterion comment="alt-openssl11-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1775146316" version="1">
      <metadata>
        <title>alt-openssl11: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1775146316" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1775146316" source="CLSA"/>
        <reference ref_id="CVE-2024-0727" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-0727" source="CVE"/>
        <reference ref_id="CVE-2023-5678" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2023-5678" source="CVE"/>
        <description>- CVE-2023-5678: fix excessive time in DH check/generation with large Q
  parameter by adding bounds checks in DH_check_pub_key and DH_generate_key
- CVE-2024-0727: fix PKCS12 decoding NULL pointer dereference by adding NULL
  checks where ContentInfo data can be NULL</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-02"/>
          <updated date="2026-04-02"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-0727" impact="moderate" public="20240126">CVE-2024-0727</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-606" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2023-5678" impact="moderate" public="20231106">CVE-2023-5678</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 1:1.1.1w-3.2.el10" test_ref="oval:com.tuxcare.clsa:tst:1775146316001"/>
        <criterion comment="alt-openssl11 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653002"/>
        <criterion comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.2.el10" test_ref="oval:com.tuxcare.clsa:tst:1775146316002"/>
        <criterion comment="alt-openssl11-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653004"/>
        <criterion comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.2.el10" test_ref="oval:com.tuxcare.clsa:tst:1775146316003"/>
        <criterion comment="alt-openssl11-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1776705233" version="1">
      <metadata>
        <title>alt-openssl11: Fix of 4 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1776705233" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1776705233" source="CLSA"/>
        <reference ref_id="CVE-2026-28389" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28389" source="CVE"/>
        <reference ref_id="CVE-2026-28390" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28390" source="CVE"/>
        <reference ref_id="CVE-2026-28388" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28388" source="CVE"/>
        <reference ref_id="CVE-2026-28387" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28387" source="CVE"/>
        <description>- CVE-2026-28387: fix use-after-free in DANE client code by using X509_free()
  instead of OPENSSL_free() to properly release reference-counted X509 objects
- CVE-2026-28388: fix NULL pointer dereference when processing a delta CRL
  that has a Delta CRL Indicator but lacks a CRL Number extension
- CVE-2026-28389: fix NULL pointer dereference in CMS KeyAgreeRecipientInfo
  processing when KeyEncryptionAlgorithmIdentifier omits the optional
  parameter field, by using safe X509_ALGOR_get0() extraction
- CVE-2026-28390: fix NULL pointer dereference in CMS KeyTransportRecipientInfo
  processing when RSA-OAEP SourceFunc parameters are missing, by using safe
  X509_ALGOR_get0() extraction and OPENSSL_memdup() for label data</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-20"/>
          <updated date="2026-04-20"/>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-166" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28389" impact="moderate" public="20260407">CVE-2026-28389</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28390" impact="important" public="20260407">CVE-2026-28390</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28388" impact="moderate" public="20260407">CVE-2026-28388</cve>
          <cve cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1341" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28387" impact="low" public="20260407">CVE-2026-28387</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 1:1.1.1w-3.3.el10" test_ref="oval:com.tuxcare.clsa:tst:1776705233001"/>
        <criterion comment="alt-openssl11 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653002"/>
        <criterion comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.3.el10" test_ref="oval:com.tuxcare.clsa:tst:1776705233002"/>
        <criterion comment="alt-openssl11-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653004"/>
        <criterion comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.3.el10" test_ref="oval:com.tuxcare.clsa:tst:1776705233003"/>
        <criterion comment="alt-openssl11-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1781801595" version="1">
      <metadata>
        <title>alt-openssl11: Fix of CVE-2026-45447</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1781801595" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1781801595" source="CLSA"/>
        <reference ref_id="CVE-2026-45447" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-45447" source="CVE"/>
        <description>- CVE-2026-45447: fix use-after-free in PKCS7_verify triggered by a crafted
  PKCS#7 / S-MIME message with an empty digestAlgorithms ASN.1 SET, which made
  OpenSSL free a caller-owned BIO; free the BIO chain explicitly and stop at
  the caller-supplied indata BIO</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-18"/>
          <updated date="2026-06-18"/>
          <cve cvss3="9.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-45447" impact="critical" public="20260609">CVE-2026-45447</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 1:1.1.1w-3.4.el10" test_ref="oval:com.tuxcare.clsa:tst:1781801595001"/>
        <criterion comment="alt-openssl11 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653002"/>
        <criterion comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.4.el10" test_ref="oval:com.tuxcare.clsa:tst:1781801595002"/>
        <criterion comment="alt-openssl11-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653004"/>
        <criterion comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.4.el10" test_ref="oval:com.tuxcare.clsa:tst:1781801595003"/>
        <criterion comment="alt-openssl11-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785918695" version="1">
      <metadata>
        <title>alt-openssl11: Fix of CVE-2025-69419</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785918695" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1785918695" source="CLSA"/>
        <reference ref_id="CVE-2025-69419" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-69419" source="CVE"/>
        <description>- HollowByte: grow the handshake init_buf incrementally as data is received
  instead of pre-allocating the full peer-declared message size, so a peer
  that claims a large message but never sends it can no longer strand memory
  (ELS-2635). Backport of OpenSSL 3.0 commit c5785a5e35 (PR #30794); handled
  by OpenSSL as a "bug or hardening" fix with no CVE assigned</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-05"/>
          <updated date="2026-08-05"/>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" cwe="CWE-787" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-69419" impact="important" public="20260127">CVE-2025-69419</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 1:1.1.1w-3.5.el10" test_ref="oval:com.tuxcare.clsa:tst:1785918695001"/>
        <criterion comment="alt-openssl11 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653002"/>
        <criterion comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.5.el10" test_ref="oval:com.tuxcare.clsa:tst:1785918695002"/>
        <criterion comment="alt-openssl11-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653004"/>
        <criterion comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.5.el10" test_ref="oval:com.tuxcare.clsa:tst:1785918695003"/>
        <criterion comment="alt-openssl11-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1786474088" version="1">
      <metadata>
        <title>alt-openssl11: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1786474088" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1786474088" source="CLSA"/>
        <reference ref_id="CVE-2026-34180" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-34180" source="CVE"/>
        <reference ref_id="CVE-2026-42766" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-42766" source="CVE"/>
        <description>- CVE-2026-34180: asn1: avoid content length truncation in asn1_ex_c2i() so a
  primitive element longer than 2GB can no longer cause a heap buffer over-read
- CVE-2026-42766: cms: check that PasswordRecipientInfo.keyDerivationAlgorithm
  is present before dereferencing it, avoiding a NULL pointer dereference</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-11"/>
          <updated date="2026-08-11"/>
          <cve cvss3="8.2/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-34180" impact="important" public="20260609">CVE-2026-34180</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-42766" impact="important" public="20260609">CVE-2026-42766</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 1:1.1.1w-3.6.el10" test_ref="oval:com.tuxcare.clsa:tst:1786474088001"/>
        <criterion comment="alt-openssl11 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653002"/>
        <criterion comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.6.el10" test_ref="oval:com.tuxcare.clsa:tst:1786474088002"/>
        <criterion comment="alt-openssl11-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653004"/>
        <criterion comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.6.el10" test_ref="oval:com.tuxcare.clsa:tst:1786474088003"/>
        <criterion comment="alt-openssl11-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789481020" version="1">
      <metadata>
        <title>alt-libxml2: Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789481020" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789481020" source="CLSA"/>
        <reference ref_id="CVE-2026-86140" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86140" source="CVE"/>
        <reference ref_id="CVE-2026-86138" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86138" source="CVE"/>
        <reference ref_id="CVE-2026-86137" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86137" source="CVE"/>
        <reference ref_id="CVE-2025-24928" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-24928" source="CVE"/>
        <reference ref_id="CVE-2026-86144" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86144" source="CVE"/>
        <reference ref_id="CVE-2026-86142" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86142" source="CVE"/>
        <reference ref_id="CVE-2026-86141" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86141" source="CVE"/>
        <reference ref_id="CVE-2026-86143" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86143" source="CVE"/>
        <description>- CVE-2026-86137: out-of-bounds read in the NXT macro in xmlFAParsePosCharGroup
- CVE-2026-86138: integer overflow and heap buffer overflow in xmlDictAddQString
- CVE-2025-24928: stale-length bounds check inside the xmlSnprintfElements loop
  (upstream 8c8753ad); this is the stack overflow reachable on 2.10.2
- CVE-2026-86140: unchecked strcat at the entry and exit of xmlSnprintfElements
  (upstream d1686f91); hardening only on 2.10.2, callers pass an emptied buffer
- CVE-2026-86141: NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure
- CVE-2026-86142: heap buffer overflow in xmlXPtrEvalXPtrPart from xpointer length saturation
- CVE-2026-86143: negative lengths reaching write callbacks in xmlIO
- CVE-2026-86144: xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate
  parseFlags; the include context now inherits every document parse flag
  (NOENT, RECOVER and HUGE included), not only NONET</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-15"/>
          <updated date="2026-09-15"/>
          <cve cwe="CWE-121" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86140" impact="unknown" public="20260905">CVE-2026-86140</cve>
          <cve cwe="CWE-190" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86138" impact="unknown" public="20260905">CVE-2026-86138</cve>
          <cve cwe="CWE-125" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86137" impact="unknown" public="20260905">CVE-2026-86137</cve>
          <cve cvss3="7.7/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" cwe="CWE-121" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-24928" impact="important" public="20250218">CVE-2025-24928</cve>
          <cve cwe="CWE-669" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86144" impact="unknown" public="20260905">CVE-2026-86144</cve>
          <cve cwe="CWE-122" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86142" impact="unknown" public="20260905">CVE-2026-86142</cve>
          <cve cwe="CWE-252" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86141" impact="unknown" public="20260905">CVE-2026-86141</cve>
          <cve cwe="CWE-192" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86143" impact="unknown" public="20260905">CVE-2026-86143</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-libxml2 is earlier than 0:2.10.2-6.el10" test_ref="oval:com.tuxcare.clsa:tst:1789481020001"/>
        <criterion comment="alt-libxml2 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020002"/>
        <criterion comment="alt-libxml2-devel is earlier than 0:2.10.2-6.el10" test_ref="oval:com.tuxcare.clsa:tst:1789481020003"/>
        <criterion comment="alt-libxml2-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020004"/>
        <criterion comment="alt-libxml2-static is earlier than 0:2.10.2-6.el10" test_ref="oval:com.tuxcare.clsa:tst:1789481020005"/>
        <criterion comment="alt-libxml2-static isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789640312" version="1">
      <metadata>
        <title>alt-libxml2: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789640312" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789640312" source="CLSA"/>
        <reference ref_id="CVE-2024-56171" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-56171" source="CVE"/>
        <reference ref_id="CVE-2026-6653" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-6653" source="CVE"/>
        <description>- CVE-2024-56171: use-after-free after xmlSchemaItemListAdd in the XML Schema
  identity-constraint code (xmlSchemaIDCFillNodeTables,
  xmlSchemaBubbleIDCNodeTables)
- CVE-2026-6653: use-after-free in xmlParseInternalSubset; xmlPushInput()
  returned -1 for a parameter entity input it had already pushed, so the caller
  freed an input stream that ctxt-&gt;input still pointed at. Reachable through the
  entity amplification check carried by 2.10.2 for CVE-2021-3541, which this
  keeps in place. Also guards the xmlSkipBlankChars() loop on XML_PARSER_EOF
  (upstream e129c1d1), without which the same document spins at 100% CPU once
  the input is no longer freed</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-56171" impact="critical" public="20250218">CVE-2024-56171</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-6653" impact="critical" public="20260622">CVE-2026-6653</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-libxml2 is earlier than 0:2.10.2-7.el10" test_ref="oval:com.tuxcare.clsa:tst:1789640312001"/>
        <criterion comment="alt-libxml2 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020002"/>
        <criterion comment="alt-libxml2-devel is earlier than 0:2.10.2-7.el10" test_ref="oval:com.tuxcare.clsa:tst:1789640312002"/>
        <criterion comment="alt-libxml2-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020004"/>
        <criterion comment="alt-libxml2-static is earlier than 0:2.10.2-7.el10" test_ref="oval:com.tuxcare.clsa:tst:1789640312003"/>
        <criterion comment="alt-libxml2-static isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789643585" version="1">
      <metadata>
        <title>alt-krb5: Fix of 6 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789643585" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789643585" source="CLSA"/>
        <reference ref_id="CVE-2020-28196" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2020-28196" source="CVE"/>
        <reference ref_id="CVE-2024-37370" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-37370" source="CVE"/>
        <reference ref_id="CVE-2022-42898" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-42898" source="CVE"/>
        <reference ref_id="CVE-2024-37371" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-37371" source="CVE"/>
        <reference ref_id="CVE-2018-5709" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2018-5709" source="CVE"/>
        <reference ref_id="CVE-2021-36222" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2021-36222" source="CVE"/>
        <description>- CVE-2018-5709: bounds-check key and name counts when loading a KDB dump
- CVE-2020-28196: add recursion limit for ASN.1 indefinite lengths
- CVE-2021-36222: fix KDC null deref on bad encrypted challenge
- CVE-2022-42898: fix integer overflows in PAC parsing
- CVE-2024-37370: verify the Extra Count field of CFX wrap tokens
- CVE-2024-37371: reject GSS message tokens with invalid length fields
- Bound dbentry-&gt;e_length when loading a KDB dump (upstream a9654198); the
  last unguarded 32-to-16-bit assignment in the function CVE-2018-5709
  bounds
- Validate the PAC length in mspac_internalize() (upstream 63ae6a8d); the
  serialized length reaching krb5_pac_parse() was unchecked. Adds the internal
  helper k5_ser_unpack_len to libkrb5.exports, as upstream does; no public
  interface changes
- Carry the t_invalid.c regression tests from upstream 55fbf435, split across
  the CVE-2024-37370 and CVE-2024-37371 patches to match the code split.
  test_cfx_altered_ec is the case that fails without the 37370 fix and
  test_cfx_large_ec the one that fails without the 37371 fix; the other two
  carried cases do not discriminate on 1.17 and are noted as such in the
  patch headers. Test-only: no shipped binary changes</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-674" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2020-28196" impact="important" public="20201106">CVE-2020-28196</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-37370" impact="important" public="20240628">CVE-2024-37370</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-42898" impact="important" public="20221225">CVE-2022-42898</cve>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-37371" impact="critical" public="20240628">CVE-2024-37371</cve>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-190" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2018-5709" impact="important" public="20180116">CVE-2018-5709</cve>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2021-36222" impact="important" public="20210722">CVE-2021-36222</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-krb5-devel is earlier than 0:1.17-14.el10" test_ref="oval:com.tuxcare.clsa:tst:1789643585001"/>
        <criterion comment="alt-krb5-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789643585002"/>
        <criterion comment="alt-krb5-libs is earlier than 0:1.17-14.el10" test_ref="oval:com.tuxcare.clsa:tst:1789643585003"/>
        <criterion comment="alt-krb5-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789643585004"/>
        <criterion comment="alt-krb5-pkinit is earlier than 0:1.17-14.el10" test_ref="oval:com.tuxcare.clsa:tst:1789643585005"/>
        <criterion comment="alt-krb5-pkinit isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789643585006"/>
        <criterion comment="alt-krb5-server is earlier than 0:1.17-14.el10" test_ref="oval:com.tuxcare.clsa:tst:1789643585007"/>
        <criterion comment="alt-krb5-server isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789643585008"/>
        <criterion comment="alt-krb5-server-ldap is earlier than 0:1.17-14.el10" test_ref="oval:com.tuxcare.clsa:tst:1789643585009"/>
        <criterion comment="alt-krb5-server-ldap isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789643585010"/>
        <criterion comment="alt-krb5-workstation is earlier than 0:1.17-14.el10" test_ref="oval:com.tuxcare.clsa:tst:1789643585011"/>
        <criterion comment="alt-krb5-workstation isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789643585012"/>
        <criterion comment="alt-libkadm5 is earlier than 0:1.17-14.el10" test_ref="oval:com.tuxcare.clsa:tst:1789643585013"/>
        <criterion comment="alt-libkadm5 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789643585014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789647012" version="1">
      <metadata>
        <title>alt-openssl11: Fix of CVE-2026-54874</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789647012" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012" source="CLSA"/>
        <reference ref_id="CVE-2026-54874" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-54874" source="CVE"/>
        <description>- CVE-2026-54874: dtls: buffer only a record's own on-wire bytes in
  dtls1_buffer_record() instead of taking over the whole read buffer, and lower
  the next-epoch record queue cap from 100 to 16, so a peer sending tiny
  next-epoch records can no longer pin ~1.7MB of heap per connection</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cwe="CWE-405" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-54874" impact="unknown" public="20260825">CVE-2026-54874</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 1:1.1.1w-3.8.el10" test_ref="oval:com.tuxcare.clsa:tst:1789647012001"/>
        <criterion comment="alt-openssl11 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653002"/>
        <criterion comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.8.el10" test_ref="oval:com.tuxcare.clsa:tst:1789647012002"/>
        <criterion comment="alt-openssl11-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653004"/>
        <criterion comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.8.el10" test_ref="oval:com.tuxcare.clsa:tst:1789647012003"/>
        <criterion comment="alt-openssl11-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1774531653006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789667016" version="1">
      <metadata>
        <title>alt-libxml2: Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789667016" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789667016" source="CLSA"/>
        <reference ref_id="CVE-2026-11979" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-11979" source="CVE"/>
        <reference ref_id="CVE-2025-32415" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-32415" source="CVE"/>
        <reference ref_id="CVE-2022-49043" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-49043" source="CVE"/>
        <reference ref_id="CVE-2025-6021" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-6021" source="CVE"/>
        <reference ref_id="CVE-2022-40303" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-40303" source="CVE"/>
        <reference ref_id="CVE-2022-40304" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-40304" source="CVE"/>
        <reference ref_id="CVE-2024-25062" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-25062" source="CVE"/>
        <reference ref_id="CVE-2025-27113" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-27113" source="CVE"/>
        <description>- CVE-2025-27113: NULL pointer dereference in xmlPatMatch(). An explicit
  child:: axis step compiled to XML_OP_CHILD, an op that accepts a document
  node and does not advance the current node, so a pattern such as
  "/child::name" matched against a document node reached the unguarded
  node-&gt;parent dereference in the XML_OP_ROOT case. Compile child:: to
  XML_OP_ELEM like the implicit axis (upstream 503f788e), which also makes
  the DOM matcher agree with the streaming matcher. Upstream fixed only the
  compiler side; the XML_OP_ROOT dereference is left unguarded here as it is
  upstream, and no in-tree caller can reach it
- CVE-2025-32415: heap out-of-bounds read during XML Schema identity-constraint
  validation. xmlSchemaIDCFillNodeTables() snapshotted the IDC node-table length
  before its target loop, but the loop shrinks the table when it moves a
  duplicate key-sequence to bind-&gt;dupls. With the stale length the loop rescans
  slots past the live end of the table and, once the table is empty, evaluates
  bind-&gt;nodeTable[-1], reading one element before the allocation and driving the
  node count negative. Use the live bind-&gt;nbNodes for both the loop guard and
  the loop terminator (upstream 384cc7c1, v2.13.8; master twin 487ee1d8,
  v2.14.2)
- CVE-2025-6021: fix integer overflow in xmlBuildQName() (tree.c). The
  prefix and local-name lengths were held in int and summed in int
  arithmetic, so a long enough QName made lenn + lenp + 2 wrap negative,
  which both defeated the buffer-size test -- handing back a caller's
  50-byte stack buffer -- and undersized the xmlMallocAtomic() allocation,
  letting the following memcpy()s and the NUL store write out of bounds.
  The lengths are now size_t, a negative len is rejected, and the sum is
  bounded against SIZE_MAX before it is formed. Backport of upstream
  17d950ae33c23f87692aa179bacedb6743f3188a.
- CVE-2026-11979: multiple stack-based buffer overflows in the xmlcatalog
  utility's --shell mode. usershell() copied the command token, the
  argument tail and the argument vector of a line of user input into the
  fixed-size command[100], arg[400] and argv[20] stack buffers with no
  bounds check, so a single over-long line corrupted the stack frame. All
  three copy loops are now bounded and reject over-long input with a
  diagnostic (upstream cd48d441, first released in v2.15.4). Only the
  xmlcatalog command-line utility is affected; no library entry point
  reaches usershell()
- xmlcatalog: reject --add/--del invocations that run off the end of argv
  (upstream b1fea45b). Not a CVE and not part of CVE-2026-11979; carried
  alongside it because upstream shipped both in the same release and both
  touch xmlcatalog.c. Without it, "xmlcatalog --add a" reads argv[4] past the
  end of the argument vector and passes whatever follows - in practice a
  process environment string - to xmlCatalogAdd()</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-121" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-11979" impact="important" public="20260629">CVE-2026-11979</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1284" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-32415" impact="important" public="20250417">CVE-2025-32415</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-49043" impact="important" public="20250126">CVE-2022-49043</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-787" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-6021" impact="important" public="20250612">CVE-2025-6021</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-40303" impact="important" public="20221123">CVE-2022-40303</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-415" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-40304" impact="important" public="20221123">CVE-2022-40304</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-25062" impact="important" public="20240204">CVE-2024-25062</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-27113" impact="important" public="20250218">CVE-2025-27113</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-libxml2 is earlier than 0:2.10.2-9.el10" test_ref="oval:com.tuxcare.clsa:tst:1789667016001"/>
        <criterion comment="alt-libxml2 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020002"/>
        <criterion comment="alt-libxml2-devel is earlier than 0:2.10.2-9.el10" test_ref="oval:com.tuxcare.clsa:tst:1789667016002"/>
        <criterion comment="alt-libxml2-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020004"/>
        <criterion comment="alt-libxml2-static is earlier than 0:2.10.2-9.el10" test_ref="oval:com.tuxcare.clsa:tst:1789667016003"/>
        <criterion comment="alt-libxml2-static isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789481020006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789720399" version="1">
      <metadata>
        <title>alt-pcre: Fix of CVE-2019-20838</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 10</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789720399" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789720399" source="CLSA"/>
        <reference ref_id="CVE-2019-20838" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2019-20838" source="CVE"/>
        <description>- On el10 only, export LDFLAGS with -Wl,-rpath=%{_libdir} before configure.
  The el10 toolchain emits neither RPATH nor RUNPATH, so
  /opt/alt/pcre/usr/bin/pcregrep failed to start with "libpcre.so.1 =&gt; not
  found" even though the package ships that library, and the QA integrity
  check flagged it. Confirmed with readelf: el6, el7 and el8 all carry
  RPATH=/opt/alt/pcre/usr/lib64 implicitly from libtool and are left alone.
- This is a live defect, not a regression: the already-released
  alt-pcre-8.42-1.el10 has no RPATH either. The %if rhel &gt;= 10 QA_RPATHS
  override above only relaxes the rpath checker; it never produced an rpath.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cvss2="4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2019-20838" impact="important" public="20200615">CVE-2019-20838</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:10</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-pcre is earlier than 0:8.45-2.el10" test_ref="oval:com.tuxcare.clsa:tst:1789720399001"/>
        <criterion comment="alt-pcre isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789720399002"/>
        <criterion comment="alt-pcre-devel is earlier than 0:8.45-2.el10" test_ref="oval:com.tuxcare.clsa:tst:1789720399003"/>
        <criterion comment="alt-pcre-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1789720399004"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11 is earlier than 1:1.1.1w-3.1.el10" id="oval:com.tuxcare.clsa:tst:1774531653001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-openssl11 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1774531653002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.1.el10" id="oval:com.tuxcare.clsa:tst:1774531653003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-openssl11-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1774531653004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.1.el10" id="oval:com.tuxcare.clsa:tst:1774531653005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-openssl11-libs isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1774531653006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11 is earlier than 1:1.1.1w-3.2.el10" id="oval:com.tuxcare.clsa:tst:1775146316001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1775146316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.2.el10" id="oval:com.tuxcare.clsa:tst:1775146316002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1775146316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.2.el10" id="oval:com.tuxcare.clsa:tst:1775146316003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1775146316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11 is earlier than 1:1.1.1w-3.3.el10" id="oval:com.tuxcare.clsa:tst:1776705233001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776705233001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.3.el10" id="oval:com.tuxcare.clsa:tst:1776705233002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776705233001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.3.el10" id="oval:com.tuxcare.clsa:tst:1776705233003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776705233001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11 is earlier than 1:1.1.1w-3.4.el10" id="oval:com.tuxcare.clsa:tst:1781801595001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781801595001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.4.el10" id="oval:com.tuxcare.clsa:tst:1781801595002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781801595001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.4.el10" id="oval:com.tuxcare.clsa:tst:1781801595003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781801595001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11 is earlier than 1:1.1.1w-3.5.el10" id="oval:com.tuxcare.clsa:tst:1785918695001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785918695001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.5.el10" id="oval:com.tuxcare.clsa:tst:1785918695002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785918695001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.5.el10" id="oval:com.tuxcare.clsa:tst:1785918695003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785918695001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11 is earlier than 1:1.1.1w-3.6.el10" id="oval:com.tuxcare.clsa:tst:1786474088001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786474088001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.6.el10" id="oval:com.tuxcare.clsa:tst:1786474088002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786474088001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.6.el10" id="oval:com.tuxcare.clsa:tst:1786474088003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786474088001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2 is earlier than 0:2.10.2-6.el10" id="oval:com.tuxcare.clsa:tst:1789481020001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789481020001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-libxml2 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789481020002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2-devel is earlier than 0:2.10.2-6.el10" id="oval:com.tuxcare.clsa:tst:1789481020003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789481020001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-libxml2-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789481020004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2-static is earlier than 0:2.10.2-6.el10" id="oval:com.tuxcare.clsa:tst:1789481020005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789481020001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-libxml2-static isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789481020006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2 is earlier than 0:2.10.2-7.el10" id="oval:com.tuxcare.clsa:tst:1789640312001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789640312001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2-devel is earlier than 0:2.10.2-7.el10" id="oval:com.tuxcare.clsa:tst:1789640312002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789640312001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2-static is earlier than 0:2.10.2-7.el10" id="oval:com.tuxcare.clsa:tst:1789640312003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789640312001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-krb5-devel is earlier than 0:1.17-14.el10" id="oval:com.tuxcare.clsa:tst:1789643585001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643585001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-krb5-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789643585002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-krb5-libs is earlier than 0:1.17-14.el10" id="oval:com.tuxcare.clsa:tst:1789643585003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643585001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-krb5-libs isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789643585004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-krb5-pkinit is earlier than 0:1.17-14.el10" id="oval:com.tuxcare.clsa:tst:1789643585005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643585001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-krb5-pkinit isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789643585006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-krb5-server is earlier than 0:1.17-14.el10" id="oval:com.tuxcare.clsa:tst:1789643585007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643585001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-krb5-server isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789643585008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-krb5-server-ldap is earlier than 0:1.17-14.el10" id="oval:com.tuxcare.clsa:tst:1789643585009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643585001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-krb5-server-ldap isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789643585010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-krb5-workstation is earlier than 0:1.17-14.el10" id="oval:com.tuxcare.clsa:tst:1789643585011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643585001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-krb5-workstation isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789643585012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libkadm5 is earlier than 0:1.17-14.el10" id="oval:com.tuxcare.clsa:tst:1789643585013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643585001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-libkadm5 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789643585014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643585013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11 is earlier than 1:1.1.1w-3.8.el10" id="oval:com.tuxcare.clsa:tst:1789647012001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789647012001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-devel is earlier than 1:1.1.1w-3.8.el10" id="oval:com.tuxcare.clsa:tst:1789647012002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789647012001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-openssl11-libs is earlier than 1:1.1.1w-3.8.el10" id="oval:com.tuxcare.clsa:tst:1789647012003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1774531653005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789647012001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2 is earlier than 0:2.10.2-9.el10" id="oval:com.tuxcare.clsa:tst:1789667016001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789667016001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2-devel is earlier than 0:2.10.2-9.el10" id="oval:com.tuxcare.clsa:tst:1789667016002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789667016001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-libxml2-static is earlier than 0:2.10.2-9.el10" id="oval:com.tuxcare.clsa:tst:1789667016003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789481020005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789667016001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-pcre is earlier than 0:8.45-2.el10" id="oval:com.tuxcare.clsa:tst:1789720399001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789720399001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789720399001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-pcre isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789720399002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789720399001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-pcre-devel is earlier than 0:8.45-2.el10" id="oval:com.tuxcare.clsa:tst:1789720399003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789720399003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789720399001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-pcre-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1789720399004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789720399003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1774531653002"/>
    </red-def:rpminfo_test>
  </tests>
  <objects>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1774531653001" version="1">
      <red-def:name>alt-openssl11</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1774531653003" version="1">
      <red-def:name>alt-openssl11-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1774531653005" version="1">
      <red-def:name>alt-openssl11-libs</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789481020001" version="1">
      <red-def:name>alt-libxml2</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789481020003" version="1">
      <red-def:name>alt-libxml2-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789481020005" version="1">
      <red-def:name>alt-libxml2-static</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789643585001" version="1">
      <red-def:name>alt-krb5-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789643585003" version="1">
      <red-def:name>alt-krb5-libs</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789643585005" version="1">
      <red-def:name>alt-krb5-pkinit</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789643585007" version="1">
      <red-def:name>alt-krb5-server</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789643585009" version="1">
      <red-def:name>alt-krb5-server-ldap</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789643585011" version="1">
      <red-def:name>alt-krb5-workstation</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789643585013" version="1">
      <red-def:name>alt-libkadm5</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789720399001" version="1">
      <red-def:name>alt-pcre</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1789720399003" version="1">
      <red-def:name>alt-pcre-devel</red-def:name>
    </red-def:rpminfo_object>
  </objects>
  <states>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1774531653001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:1.1.1w-3.1.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1774531653002" version="1">
      <red-def:signature_keyid operation="equals">d07bf2a08d50eb66</red-def:signature_keyid>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1775146316001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:1.1.1w-3.2.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1776705233001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:1.1.1w-3.3.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1781801595001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:1.1.1w-3.4.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785918695001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:1.1.1w-3.5.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1786474088001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:1.1.1w-3.6.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1789481020001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.10.2-6.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1789640312001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.10.2-7.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1789643585001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.17-14.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1789647012001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:1.1.1w-3.8.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1789667016001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.10.2-9.el10</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1789720399001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:8.45-2.el10</red-def:evr>
    </red-def:rpminfo_state>
  </states>
</oval_definitions>
