OpenSSL Product Security Update Advisory

OpenSSL Product Security Update Advisory

Overview

A security update has been released to address a vulnerability in OpenSSL products. users of these products should update to the latest version.

Affected Products and Versions

  • OpenSSL 4.0 or later, but not earlier than 4.0.1.
  • OpenSSL 3.6 or later but less than 3.6.3.
  • OpenSSL 3.5 or later but less than 3.5.7.
  • OpenSSL 3.4 or later but less than 3.4.6.
  • OpenSSL 3.0 or later but less than 3.0.21.
  • OpenSSL 1.1.1 or later but less than 1.1.1zh.
  • OpenSSL 1.0.2 or later but less than 1.0.2zq.

Resolved Vulnerabilities

  • CVE-2026-34180: Heap buffer overread vulnerability in OpenSSL.
  • CVE-2026-42764: Denial of Service vulnerability in OpenSSL.
  • CVE-2026-42765: Denial of Service vulnerability in OpenSSL.
  • CVE-2026-45445: Authentication bypass vulnerability in OpenSSL.
  • CVE-2026-45447: Use-After-Free vulnerability in OpenSSL (flaw that reuses memory that has already been freed).
  • CVE-2026-7383: Heap buffer overflow vulnerability in OpenSSL.
  • CVE-2026-9076: Out-of-bounds read vulnerability in OpenSSL.

Patch versions

  • CVE-2026-34180, CVE-2026-7383, CVE-2026-9076, CVE-2026-45447: 4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21, 1.1.1zh, 1.0.2zq.
  • Cve-2026-42764: 4.0.1, 3.6.3, 3.5.7.
  • Cve-2026-42765: 4.0.1, 3.6.3, 3.5.7.
  • Cve-2026-45445: 4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21.

See also

  • OpenSSL Security Advisory [9th June 2026].