OpenSSL 3.6.2
2026-04-08T08:52:16Z•b0f111a2b8bc929e539d4b9310ad32d3b7b263d2159d26e1f5fd893520738b16
aes-cfb-128biocmscrlcryptodaneheap-buffer-overflowhex-conversionnull-dereferenceocbopensslout-of-bounds-readpbmac1pkcs12releasersa-kemsecurity-patchtlstls1.3use-after-freex509
What happened
Multiple OpenSSL releases (3.6.2, 3.5.6, 3.4.5, 3.3.7, 3.0.20 and prior 3.6.1) are security patch releases addressing a range of vulnerabilities across libcrypto and TLS/X509/CMS code paths. Fixed issues include incorrect RSA KEM RSASVE failure handling, key-agreement group parsing errors, AES-CFB-128 out-of-bounds read on AVX-512, DANE use-after-free, null pointer dereferences when processing delta CRLs and CMS recipient info, heap buffer overflow in hexadecimal conversion, and several PKCS#12/CMS/TLS memory corruption and validation bugs. Users should upgrade to the patched releases to remed
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- openssl_releases
- Record identifier
- b0f111a2b8bc929e539d4b9310ad32d3b7b263d2159d26e1f5fd893520738b16
- Enrichment time
- 2026-04-08T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.