OpenSSL 3.6.2 lands with eight CVE fixes
ID: 22f64c13-64bb-5b3f-8f50-8b72fd8a337e
STIX ID: report--22f64c13-64bb-5b3f-8f50-8b72fd8a337e
Feed Name: Help Net Security
OpenSSL 3.6.2 patches eight CVEs across multiple components — including RSA KEM RSASVE encapsulation failures, an AES-CFB-128 out-of-bounds read on x86-64 with AVX-512, DANE use-after-free, several NULL pointer dereferences in CRL/CMS handling, and a heap buffer overflow — and also restores two behaviors regressed in 3.6.0; administrators on 3.6.x (particularly x86-64 with AVX-512) should prioritize these updates, while organizations may consider support-window differences between the 3.6 standard-support branch and the longer-term 3.5 branch when planning upgrades.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
