OpenSSL 4.0.2 Released with Important Security and Bug Fixes

Posted by hanuca on Aug 25, 2026 10:09 PM EDT
9to5linux.com; By Marcus Nestor
Mail this story
Print this story

OpenSSL 4.0.2 has been released today as the second maintenance/security update to the latest OpenSSL 4.0 series of this widely used TLS/SSL and crypto library for providing secure communications over computer networks.

Coming two and a half months after OpenSSL 4.0.1, the OpenSSL 4.0.2 release is here to address several important security vulnerabilities, including a heap buffer overflow in CMS key unwrapping (CVE-2026-63072), excessive memory use buffering DTLS records (CVE-2026-54874), and a client-side memory leak in OCSP response checking (CVE-2026-54876).

Full Story

  Nav
» Read more about: Story Type: News Story; Groups: Linux

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.