OpenSSL 3.6.1

2026-03-04T22:22:54Z7354a577179bed0ff63cb1e6beec39b2e04fc12b4ae69bd2a1b39e2d90ae643b
CVE-2025-11187CVE-2025-15467CVE-2025-15468CVE-2025-15469CVE-2025-66199CVE-2025-68160CVE-2025-69418CVE-2025-69419CVE-2025-69420CVE-2025-69421CVE-2026-22795CVE-2026-22796asn1biobuffer-overflowcmscryptographycveheap-out-of-boundsmemory-allocationnull-dereferenceocbopensslopenssl-dgstpkcs12pkcs7security-patchtls1.3utf8vulnerability

What happened

Multiple OpenSSL security-patch releases (notably 3.6.1, 3.5.5, 3.4.4, 3.3.6 and 3.0.19) address a set of high-severity and other vulnerabilities across CMS, PKCS#12/PKCS7/ASN.1 handling, TLS 1.3 certificate compression, BIO line buffering, OCB low-level calls, and the openssl dgst one-shot path. Fixes include stack buffer overflow, heap out-of-bounds writes, NULL dereferences, excessive memory allocation, unauthenticated trailing data in OCB, UTF‑8 conversion overflow, and ASN.1 type/validation issues. Users should upgrade to patched releases to mitigate potential remote or local crashes, out

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
openssl_releases
Record identifier
7354a577179bed0ff63cb1e6beec39b2e04fc12b4ae69bd2a1b39e2d90ae643b
Enrichment time
2026-03-04T22:22:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OpenSSL 3.6.1 · Baitaphish