OpenSSL 4.0.1
- Fixed regression that led to openssl pkey command crash when encrypting a private key with interactively provided password
- Fixed regression that led to openssl s_client -adv prematurely terminating when reading 16384 bytes in one read() call
- Fixed heap use-after-free in PKCS7_verify()
- Fixed CMS AuthEnvelopedData processing that may accept forged messages
- Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler
- Fixed double-free when checking OCSP stapled response
- Fixed NULL pointer dereference in QUIC server initial packet handling
- Fixed AES-OCB IV ignored on EVP_Cipher() path
- Fixed possible heap buffer overflow in ASN.1 multibyte string conversion
- Fixed out-of-bounds read in CMS password-based decryption
- Fixed heap buffer over-read in ASN.1 content parsing
- Fixed PKCS#12 files with PBMAC1 accepted with short HMAC keys
- Fixed NULL dereference in certificate verification with OCSP checking
- Fixed possible NULL dereference in password-based CMS decryption
- Fixed NULL pointer dereference in CRMF EncryptedValue decryption
- Fixed multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
- Fixed trust anchor substitution via cert/issuer typo in CMP rootCaKeyUpdate
- Fixed FFC-DH peer validation using attacker-supplied q
- Fixed possible out of bounds read in X509_VERIFY_PARAM_set1_email()
- Fixed incorrect tag processing for empty messages in AES-GCM-SIV and AES-SIV modes
OpenSSL 4.0.1 is a security patch release. The most severe CVE fixed in this release is High.
This release incorporates the following bug fixes and mitigations:
-
Fixed heap use-after-free in
PKCS7_verify(). (CVE-2026-45447) -
Fixed CMS
AuthEnvelopedDataprocessing may accept forged messages. (CVE-2026-34182) -
Fixed unbounded memory growth in the QUIC
PATH_CHALLENGEhandler. (CVE-2026-34183) -
Fixed double-free when checking OCSP stapled response. (CVE-2026-35188)
-
Fixed NULL pointer dereference in QUIC server initial packet handling. (CVE-2026-42764)
-
Fixed AES-OCB IV ignored on
EVP_Cipher()path. (CVE-2026-45445) -
Fixed possible heap buffer overflow in ASN.1 multibyte string conversion. (CVE-2026-7383)
-
Fixed out-of-bounds read in CMS password-based decryption. (CVE-2026-9076)
-
Fixed heap buffer over-read in ASN.1 content parsing. (CVE-2026-34180)
-
Fixed PKCS#12 files with PBMAC1 are accepted with short HMAC keys. (CVE-2026-34181)
-
Fixed NULL dereference in certificate verification with OCSP Checking. (CVE-2026-42765)
-
Fixed possible NULL dereference in password-dased CMS decryption. (CVE-2026-42766)
-
Fixed NULL pointer dereference in CRMF
EncryptedValuedecryption. (CVE-2026-42767) -
Fixed multi-
RecipientInfoBleichenbacher Oracle inCMS_decrypt()andPKCS7_decrypt(). (CVE-2026-42768) -
Fixed trust anchor substitution via
cert/issuertypo in CMProotCaKeyUpdate. (CVE-2026-42769) -
Fixed FFC-DH peer validation uses attacker-supplied
q. (CVE-2026-42770) -
Fixed possible out of bounds read in
X509_VERIFY_PARAM_set1_email(). (CVE-2026-42771) -
Fixed incorrect tag processing for empty messages in AES-GCM-SIV and AES-SIV modes. (CVE-2026-45446)
-
Fixed a regression introduced in 4.0.0 that led to a
openssl pkeycommand crash when it was invoked to encrypt a private key with password being provided interactively. -
Fixed a regression introduced in 4.0.0 that led to
openssl s_client -advcommand prematurely terminating a session when reading input of 16384 bytes in oneread()call.