OpenSSL 3.6.1
2026-03-04T22:22:54Z•7354a577179bed0ff63cb1e6beec39b2e04fc12b4ae69bd2a1b39e2d90ae643b
CVE-2025-11187CVE-2025-15467CVE-2025-15468CVE-2025-15469CVE-2025-66199CVE-2025-68160CVE-2025-69418CVE-2025-69419CVE-2025-69420CVE-2025-69421CVE-2026-22795CVE-2026-22796asn1biobuffer-overflowcmscryptographycveheap-out-of-boundsmemory-allocationnull-dereferenceocbopensslopenssl-dgstpkcs12pkcs7security-patchtls1.3utf8vulnerability
What happened
Multiple OpenSSL security-patch releases (notably 3.6.1, 3.5.5, 3.4.4, 3.3.6 and 3.0.19) address a set of high-severity and other vulnerabilities across CMS, PKCS#12/PKCS7/ASN.1 handling, TLS 1.3 certificate compression, BIO line buffering, OCB low-level calls, and the openssl dgst one-shot path. Fixes include stack buffer overflow, heap out-of-bounds writes, NULL dereferences, excessive memory allocation, unauthenticated trailing data in OCB, UTF‑8 conversion overflow, and ASN.1 type/validation issues. Users should upgrade to patched releases to mitigate potential remote or local crashes, out
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- openssl_releases
- Record identifier
- 7354a577179bed0ff63cb1e6beec39b2e04fc12b4ae69bd2a1b39e2d90ae643b
- Enrichment time
- 2026-03-04T22:22:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.