OpenSSL 3.6.2

2026-04-08T08:52:16Zb0f111a2b8bc929e539d4b9310ad32d3b7b263d2159d26e1f5fd893520738b16
aes-cfb-128biocmscrlcryptodaneheap-buffer-overflowhex-conversionnull-dereferenceocbopensslout-of-bounds-readpbmac1pkcs12releasersa-kemsecurity-patchtlstls1.3use-after-freex509

What happened

Multiple OpenSSL releases (3.6.2, 3.5.6, 3.4.5, 3.3.7, 3.0.20 and prior 3.6.1) are security patch releases addressing a range of vulnerabilities across libcrypto and TLS/X509/CMS code paths. Fixed issues include incorrect RSA KEM RSASVE failure handling, key-agreement group parsing errors, AES-CFB-128 out-of-bounds read on AVX-512, DANE use-after-free, null pointer dereferences when processing delta CRLs and CMS recipient info, heap buffer overflow in hexadecimal conversion, and several PKCS#12/CMS/TLS memory corruption and validation bugs. Users should upgrade to the patched releases to remed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
openssl_releases
Record identifier
b0f111a2b8bc929e539d4b9310ad32d3b7b263d2159d26e1f5fd893520738b16
Enrichment time
2026-04-08T08:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OpenSSL 3.6.2 · Baitaphish