OpenSSL openssl-3.4.7

openssl-3.4.7

OpenSSL 3.4.7

Security 9
  • Fixed heap buffer overflow in CMS key unwrapping
  • Fixed invalid pointer dereference in CMP server via crafted protectionAlg
  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate
  • Fixed excessive memory use buffering DTLS records for a future epoch
  • Fixed untrusted Sender DN being used as a format string in CMP response validation
  • Fixed CMP indefinite cache growth of extraCerts

From OpenSSL

OpenSSL 3.4.7 is a security patch release. The most severe CVE fixed in this release is Moderate.

This release incorporates the following bug fixes and mitigations:

  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)

  • Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)

  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)

  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)

  • Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)

  • Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)

  • Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)

  • Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)

  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

View original

Upgraded? How did it go?

Discussion