OpenSSL 4.0.2
- Fixed QUIC server being able to trigger double free when processing INITIAL packet
- Fixed heap buffer overflow in CMS key unwrapping
- Fixed invalid pointer dereference in CMP server via crafted protectionAlg
- Fixed unbounded memory growth in QUIC server incoming channel queue
- Fixed RPK server signature algorithm selection being able to dereference a missing certificate
- Fixed excessive memory use buffering DTLS records for a future epoch
- Fixed client-side memory leak in OCSP response checking
- Fixed untrusted Sender DN being used as a format string in CMP response validation
- Fixed CMP indefinite cache growth of extraCerts
- Fixed QUIC ACK-only packet retention being able to cause memory exhaustion
- Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher()
- Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode
From OpenSSL
OpenSSL 4.0.2 is a security patch release. The most severe CVE fixed in this release is Moderate.
This release incorporates the following bug fixes and mitigations:
-
Fixed QUIC server being able to trigger double free when processing
INITIALpacket. (CVE-2026-18798) -
Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)
-
Fixed invalid pointer dereference in CMP server via crafted
protectionAlg. (CVE-2026-63076) -
Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)
-
Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)
-
Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)
-
Fixed client-side memory leak in OCSP response checking. (CVE-2026-54876)
-
Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)
-
Fixed CMP indefinite cache growth of
extraCerts. (CVE-2026-63074) -
Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)
-
Fixed possibility of AEAD forgeries with empty ciphertext when using
EVP_Cipher(). (CVE-2026-75803) -
Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.