Home Content News OpenSSL 4.0.2 Patches Multiple Security Flaws Across Core Components

OpenSSL 4.0.2 Patches Multiple Security Flaws Across Core Components

0
1

OpenSSL 4.0.2 addresses multiple security vulnerabilities across CMS, DTLS, OCSP, CMP, QUIC, RPK and AEAD, while updates also reach four maintained 3.x branches.

OpenSSL, the widely used open-source TLS/SSL and cryptography library, has released OpenSSL 4.0.2, its second maintenance and security update for the OpenSSL 4.0 series, fixing multiple security vulnerabilities.

Among the key flaws addressed is a heap buffer overflow in CMS key unwrapping (CVE-2026-63072), alongside excessive memory use while buffering DTLS records (CVE-2026-54874) and a client-side memory leak during OCSP response checking (CVE-2026-54876).

The update also fixes an invalid pointer dereference in the CMP server through a crafted protectionAlg (CVE-2026-63076), unbounded memory growth in the QUIC server incoming channel queue (CVE-2026-14456), and a QUIC server double-free issue when processing an INITIAL packet (CVE-2026-18798).

Further fixes address RPK certificate handling, an untrusted Sender DN being used as a format string during CMP response validation, indefinite extraCerts cache growth, QUIC ACK-only packet memory exhaustion, and the possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher().

OpenSSL also fixed authentication-tag checking for empty ciphertexts in CCM-mode AEAD ciphers.
The project has also released OpenSSL 3.6.4, 3.5.8, 3.4.7 and 3.0.22 as security and bug-fix updates for maintained 3.x branches.

Released two and a half months after OpenSSL 4.0.1, the updates underline the need for organisations using OpenSSL to apply upstream security fixes across the versions they operate. Users are advised to patch as soon as possible or when the updates reach stable GNU/Linux distribution repositories.

Loading form…

LEAVE A REPLY

Please enter your comment!
Please enter your name here