Description:
OpenSSL has released 1.0.2, 1.1.1, 3.0.23, 3.4.8, 3.5.9, 3.6.5 and 4.0.3 to fix the vulnerabilities in various versions of OpenSSL. The details of the security update can be found at:
https://openssl-library.org/news/secadv/20260929.txt
Affected Systems:
- OpenSSL 1.0.2 prior to version 1.0.2zs
- OpenSSL 1.1.1 prior to version 1.1.1zj
- OpenSSL 3.0.0 prior to version 3.0.23
- OpenSSL 3.4.0 prior to version 3.4.8
- OpenSSL 3.5.0 prior to version 3.5.9
- OpenSSL 3.6.0 prior to version 3.6.5
- OpenSSL 4.0.0 prior to version 4.0.3
Impact:
Successful exploitation of the vulnerabilities could lead to denial of service, information disclosure, spoofing or tampering on an affected system.
Recommendation:
Patches for affected software are available. System administrators of affected systems should follow the recommendations provided by the software vendor and take immediate actions to mitigate the risk.
More Information:
- https://openssl-library.org/news/secadv/20260929.txt
- https://www.cve.org/CVERecord?id=CVE-2026-35189
- https://www.cve.org/CVERecord?id=CVE-2026-35191
- https://www.cve.org/CVERecord?id=CVE-2026-42772
- https://www.cve.org/CVERecord?id=CVE-2026-54872
- https://www.cve.org/CVERecord?id=CVE-2026-54873
- https://www.cve.org/CVERecord?id=CVE-2026-54875
- https://www.cve.org/CVERecord?id=CVE-2026-72897
- https://www.cve.org/CVERecord?id=CVE-2026-75804
- https://www.cve.org/CVERecord?id=CVE-2026-75805
- https://www.cve.org/CVERecord?id=CVE-2026-75806
- https://www.cve.org/CVERecord?id=CVE-2026-77696
- https://www.cve.org/CVERecord?id=CVE-2026-84782
- https://www.cve.org/CVERecord?id=CVE-2026-84784
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35189
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35191
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42772
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54872 (to CVE-2026-54873)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54875
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-72897
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-75804 (to CVE-2026-75806)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77696
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84782
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84784