logo

OpenSSL 3.6.2 lands with eight CVE fixes

ID: 22f64c13-64bb-5b3f-8f50-8b72fd8a337e

STIX ID: report--22f64c13-64bb-5b3f-8f50-8b72fd8a337e

Feed Name: Help Net Security

Threat Score
50/100

Date Published: 2026-04-08

Date Updated: 2026-04-28

Author: Sinisa Markovic

...
...

OpenSSL 3.6.2 patches eight CVEs across multiple components — including RSA KEM RSASVE encapsulation failures, an AES-CFB-128 out-of-bounds read on x86-64 with AVX-512, DANE use-after-free, several NULL pointer dereferences in CRL/CMS handling, and a heap buffer overflow — and also restores two behaviors regressed in 3.6.0; administrators on 3.6.x (particularly x86-64 with AVX-512) should prioritize these updates, while organizations may consider support-window differences between the 3.6 standard-support branch and the longer-term 3.5 branch when planning upgrades.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.