OpenSSL Product Security Update Advisory
Overview
A security update has been released to address a vulnerability in OpenSSL products. users of these products should update to the latest version.
Affected Products and Versions
- OpenSSL 4.0 or later, but not earlier than 4.0.1.
- OpenSSL 3.6 or later but less than 3.6.3.
- OpenSSL 3.5 or later but less than 3.5.7.
- OpenSSL 3.4 or later but less than 3.4.6.
- OpenSSL 3.0 or later but less than 3.0.21.
- OpenSSL 1.1.1 or later but less than 1.1.1zh.
- OpenSSL 1.0.2 or later but less than 1.0.2zq.
Resolved Vulnerabilities
- CVE-2026-34180: Heap buffer overread vulnerability in OpenSSL.
- CVE-2026-42764: Denial of Service vulnerability in OpenSSL.
- CVE-2026-42765: Denial of Service vulnerability in OpenSSL.
- CVE-2026-45445: Authentication bypass vulnerability in OpenSSL.
- CVE-2026-45447: Use-After-Free vulnerability in OpenSSL (flaw that reuses memory that has already been freed).
- CVE-2026-7383: Heap buffer overflow vulnerability in OpenSSL.
- CVE-2026-9076: Out-of-bounds read vulnerability in OpenSSL.
Patch versions
- CVE-2026-34180, CVE-2026-7383, CVE-2026-9076, CVE-2026-45447: 4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21, 1.1.1zh, 1.0.2zq.
- Cve-2026-42764: 4.0.1, 3.6.3, 3.5.7.
- Cve-2026-42765: 4.0.1, 3.6.3, 3.5.7.
- Cve-2026-45445: 4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21.
See also
- OpenSSL Security Advisory [9th June 2026].