OpenSSL 4.0.2 Released with Important Security and Bug Fixes
|
|
OpenSSL 4.0.2 has been released today as the second maintenance/security update to the latest OpenSSL 4.0 series of this widely used TLS/SSL and crypto library for providing secure communications over computer networks.
|
|
Coming two and a half months after OpenSSL 4.0.1, the OpenSSL 4.0.2 release is here to address several important security vulnerabilities, including a heap buffer overflow in CMS key unwrapping (CVE-2026-63072), excessive memory use buffering DTLS records (CVE-2026-54874), and a client-side memory leak in OCSP response checking (CVE-2026-54876). Full Story |
This topic does not have any threads posted yet!
You cannot post until you login.