@@ -28,6 +28,296 @@ OpenSSL Releases
2828OpenSSL 3.5
2929-----------
3030
31+ ### Changes between 3.5.8 and 3.5.9 [29 Sep 2026]
32+
33+ * Fixed DTLS retransmissions of handshake messages from a stale buffer offset.
34+
35+ Severity: High
36+
37+ Issue summary: The DTLS retransmission logic does not correctly handle
38+ a handshake message write that is suspended part-way through.
39+ The retransmitted message can be read past the message buffer
40+ and the retransmission overwrites the internal state the suspended write
41+ needs to resume correctly.
42+
43+ Impact summary: The retransmitted message can disclose a heap memory
44+ to the peer as plaintext handshake data or cause a crash and a Denial
45+ of Service when the read reaches an unmapped memory region.
46+
47+ Reported by: Laurent Gaffie (secorizon.com).
48+
49+ ([CVE-2026-84782])
50+
51+ *Ryan Hooper*
52+
53+ * Fixed excessive memory allocation in relative CRLDP processing.
54+
55+ Severity: Low
56+
57+ Issue summary: A certificate with many `nameRelativeToCRLIssuer` CRL
58+ distribution points causes disproportionate heap growth when OpenSSL caches
59+ X.509 extensions.
60+
61+ Impact summary: Receiving a crafted certificate from a malicious peer
62+ can lead to significant memory pressure and possible Denial of Service
63+ in clients or in servers that solicit client certificates.
64+
65+ Reported by: Fuzz0x (ZKSC Institute of Security Research).
66+
67+ ([CVE-2026-35189])
68+
69+ *Viktor Dukhovni*
70+
71+ * Fixed QUIC unvalidated amplification credit may be over-accounted.
72+
73+ Severity: Low
74+
75+ Issue summary: The OpenSSL QUIC server, when configured to not preform
76+ address validation, can be forced to count incoming packets multiple times
77+ in its unvalidated credit computation, leading to a violation
78+ of the [RFC 9000] unvalidated connection amplification limit of 3 times
79+ the amount of data received.
80+
81+ Impact summary: A remote attacker, who is able to spoof packets to a server
82+ using the OpenSSL QUIC implementation, might use the server
83+ for an amplification of a Distributed Denial of Service attack.
84+
85+ Reported by: Ali Firas and Nikolas Gauder (NVIDIA).
86+
87+ ([CVE-2026-35191])
88+
89+ *Neil Horman*
90+
91+ * Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC.
92+
93+ Severity: Low
94+
95+ Issue summary: The QUIC stream reassembly algorithm performance deteriorates
96+ progressively as packets are arriving out of order. The worst case has
97+ a quadratic complexity, proportional to the number of stream frames kept
98+ in the buffer for the received stream data.
99+
100+ Impact summary: A remote QUIC peer that completes the handshake can create
101+ a connection-scoped CPU pressure and potentially a Denial of Service using
102+ compliant `STREAM` frames inside the advertised receive window, with low
103+ attacker bandwidth.
104+
105+ Reported by: Saku0512 and Opal Wright (Trail of Bits) in collaboration
106+ with OpenAI
107+
108+ ([CVE-2026-42772])
109+ <!-- https://github.com/openssl/openssl/pull/32769 -->
110+
111+ *Alexandr Nedvědický*
112+
113+ * Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves.
114+
115+ Severity: Low
116+
117+ Issue summary: The generic elliptic-curve scalar multiplication, used
118+ for ECDSA and SM2 signature operations with curves that do not have
119+ a dedicated implementation, leaks information about the secret nonce
120+ through timing.
121+
122+ Impact summary: An attacker, who is able to measure signing times, may learn
123+ information about the per-signature secret nonce, which over many signatures
124+ can, via a Hidden Number Problem (lattice) attack, lead to recovery
125+ of the private key.
126+
127+ Reported by: Alicja Kario and George Pantelakis (Red Hat), based
128+ on the report of Youngjae Choi (Korea University).
129+
130+ ([CVE-2026-54872])
131+
132+ *Igor Ustinov*
133+
134+ * Fixed QUIC `STREAM` fragment metadata DoS.
135+
136+ Severity: Low
137+
138+ Issue summary: QUIC process may keep memory for QUIC packet buffer
139+ for much longer period than necessary.
140+
141+ Impact summary: Remote peer can exploit this vulnerability by sending
142+ maliciously crafted packets, making the local QUIC stack to keep the memory
143+ for packet buffers allocated. The time for which the memory remains
144+ allocated is entirely under the control of the potentially malicious remote
145+ peer.
146+
147+ Reported by: Zhen Yan (AntAISecurityLab) and Bhabani Sankar Das.
148+
149+ ([CVE-2026-54873])
150+ <!-- https://github.com/openssl/openssl/pull/32769 -->
151+
152+ *Alexandr Nedvědický*
153+
154+ * Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V.
155+
156+ Severity: Low
157+
158+ Issue summary: A non-constant-time optimized implementation of scalar
159+ point multiplication is used for SM2 private key operations on ARM64
160+ and RISC-V platforms.
161+
162+ Impact summary: An attacker able to measure the time taken by, or to observe
163+ the cache-line access pattern of, SM2 signing or decryption on an affected
164+ platform can learn information about the secret scalar.
165+
166+ Reported by: Abhinav Agarwal and Feng Xue.
167+
168+ ([CVE-2026-54875])
169+
170+ *Igor Ustinov*
171+
172+ * Fixed out-of-bounds access after `SSL_set_SSL_CTX()` during a handshake.
173+
174+ Severity: Low
175+
176+ Issue summary: A TLS server that calls `SSL_set_SSL_CTX()` to switch
177+ a connection to a different `SSL_CTX` part way through a handshake may access
178+ memory beyond the end of an internal array if the replacement context knows
179+ about more provider signature algorithms than the context the connection was
180+ created from. Applications that never call `SSL_set_SSL_CTX()`
181+ are not affected.
182+
183+ Impact summary: A remote peer may be able to cause a small out-of-bounds
184+ read, and, in some circumstances, a fixed-value out-of-bounds write,
185+ on the server heap. This may lead to a Denial of Service.
186+
187+ Reported by: Filipe Casal (Trail of Bits) in collaboration with OpenAI,
188+ Brandon Luo, Luigino Camastra (Aisle Research), and Bhargava Shastry.
189+
190+ ([CVE-2026-72897])
191+
192+ *Matt Caswell*
193+
194+ * Fixed QUIC connection-level flow control was not enforced for streams.
195+
196+ Severity: Low
197+
198+ Issue summary: OpenSSL QUIC stack does not enforce connection-level flow
199+ control for streams. Remote peers may send more bytes, as long as they fit
200+ within the stream flow control limits.
201+
202+ Impact summary: A malicious remote peer may exploit the lack of connection
203+ flow control for streams to make the QUIC stack receive ~100 MiB of memory
204+ instead of 768 KiB (default flow control window size).
205+
206+ Reportedby: Moltenbit, Bhabani Sankar Das, Saiyowa Security Team, mzfr.
207+
208+ ([CVE-2026-75804])
209+
210+ *Alexandr Nedvědický*
211+
212+ * Fixed a NULL pointer dereference in CMP client revocation response handling.
213+
214+ Severity: Low
215+
216+ Issue summary: The OpenSSL Certificate Management Protocol (CMP) client
217+ that requests a certificate revocation on the basis of a PKCS#10 CSR may
218+ dereference a NULL pointer and terminate abnormally when processing a crafted
219+ revocation response.
220+
221+ Impact summary: The NULL pointer dereference happens on a read, which
222+ leads to a crash and a Denial of Service for the affected client application.
223+
224+ Reported by: Bhabani Sankar Das.
225+
226+ ([CVE-2026-75805])
227+
228+ *Bhabani Sankar Das and Norbert Pócs*
229+
230+ * Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS.
231+
232+ Severity: Low
233+
234+ Issue summary: An established DTLS 1.2 association using an AEAD cipher suite
235+ can be terminated by a single unauthenticated datagram whose encrypted
236+ fragment is shorter than the mandatory explicit IV and authentication tag
237+ overhead.
238+
239+ Impact summary: An attacker who can send a datagram that is routed
240+ to an existing DTLS 1.2 association can tear that association down
241+ without knowing any key material. This is a Denial of Service, limited
242+ to the targeted association. There is no memory safety or confidentiality
243+ impact.
244+
245+ Reported by: Mounir IDRASSI.
246+
247+ ([CVE-2026-75806])
248+
249+ *Mounir IDRASSI*
250+
251+ * Fixed a timing side-channel in SM2 signature generation.
252+
253+ Severity: Low
254+
255+ Issue summary: SM2 signature generation uses non-constant-time arithmetic
256+ on secret values, forming a timing side-channel.
257+
258+ Impact summary: An attacker able to measure SM2 signing times may learn
259+ information about the per-signature secret nonce, which over many signatures
260+ can, via a Hidden Number Problem (lattice) attack, lead to recovery
261+ of the private key.
262+
263+ Reported by: Vladimir Tokarev.
264+
265+ ([CVE-2026-77696])
266+
267+ *Igor Ustinov and Viktor Dukhovni*
268+
269+ * Fixed an unbounded `RETIRE_CONNECTION_ID` backlog in QUIC stack
270+ implementation.
271+
272+ Severity: Low
273+
274+ Issue summary: A malicious remote peer may flood the local QUIC stack
275+ with `NEW_CONNECTION_ID` frames by avoiding a limit check on how many
276+ connection IDs the remote QUIC stack can use.
277+
278+ Impact summary: The local QUIC stack sends a `RETIRE_CONN_ID` frame
279+ for every `NEW_CONNECTION_ID` frame it receives. The `RETIRE_CONN_ID`
280+ frame is dispatched via the Control Frame Queue (CFQ). If the remote
281+ peer also withholds ACKs, then it can force the local stack to allocate
282+ up to ~400 MB (depending on ACK delay).
283+
284+ Reported by: Bhabani Sankar Das.
285+
286+ ([CVE-2026-84784])
287+
288+ *Alexandr Nedvědický*
289+
290+ * Fixed a bug where `EVP_DecryptFinal()` incorrectly reported a stale success
291+ on AES-SIV authentication failure after a preciously successful message
292+ decryption.
293+ <!-- https://github.com/openssl/openssl/pull/31610 -->
294+
295+ *Abel Thomas*
296+
297+ * Fixed a bug in `OSSL_HTTP_get()` that allowed to perform HTTPS-to-HTTP
298+ downgrade through a relative redirect.
299+ <!-- https://github.com/openssl/openssl/pull/32694 -->
300+
301+ *Mounir IDRASSI*
302+
303+ * Changed the OpenSSL FIPS provider so that every algorithm advertised
304+ with `fips=yes` property explicitly exposes a `fips-indicator` gettable
305+ context parameter, that returns 1 for an approved operation. The absence
306+ of an indicator is no longer interpreted as approval. Algorithms advertised
307+ with `fips=no` property, including X448MLKEM1024, remain unapproved
308+ and return 0 when they expose the indicator.
309+ <!-- https://github.com/openssl/openssl/pull/32913 -->
310+
311+ *Shane Lontis*
312+
313+ * Changed the compiler flags supplied to MSVC targets to no longer include
314+ `/Gs0` (resetting the minimum memory size occupied by local variables
315+ for including stack probes to the default value of 4096), as it led
316+ to mis-compilation of MD4 C implementation on ARM64.
317+ <!-- https://github.com/openssl/openssl/pull/32872 -->
318+
319+ *Norbert Pócs*
320+
31321### Changes between 3.5.7 and 3.5.8 [25 Aug 2026]
32322
33323 * Fixed QUIC server being able to trigger double free when processing `INITIAL`
@@ -22521,22 +22811,35 @@ ndif
2252122811[CVE-2026-34181]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34181
2252222812[CVE-2026-34182]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34182
2252322813[CVE-2026-34183]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34183
22814+ [CVE-2026-35189]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-35189
22815+ [CVE-2026-35191]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-35191
2252422816[CVE-2026-42764]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42764
2252522817[CVE-2026-42766]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42766
2252622818[CVE-2026-42767]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42767
2252722819[CVE-2026-42768]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42768
2252822820[CVE-2026-42769]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42769
2252922821[CVE-2026-42770]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42770
22822+ [CVE-2026-42772]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42772
2253022823[CVE-2026-45445]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45445
2253122824[CVE-2026-45446]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45446
2253222825[CVE-2026-45447]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45447
22826+ [CVE-2026-54872]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54872
22827+ [CVE-2026-54873]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54873
2253322828[CVE-2026-54874]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54874
22829+ [CVE-2026-54875]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54875
2253422830[CVE-2026-63072]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63072
2253522831[CVE-2026-63073]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63073
2253622832[CVE-2026-63074]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63074
2253722833[CVE-2026-63075]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63075
2253822834[CVE-2026-63076]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63076
22835+ [CVE-2026-72897]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-72897
2253922836[CVE-2026-75803]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75803
22837+ [CVE-2026-75804]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75804
22838+ [CVE-2026-75805]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75805
22839+ [CVE-2026-75806]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75806
22840+ [CVE-2026-77696]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-77696
22841+ [CVE-2026-84782]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782
22842+ [CVE-2026-84784]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-84784
2254022843[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations
2254122844[RFC 2578 (STD 58), section 3.5]: https://datatracker.ietf.org/doc/html/rfc2578#section-3.5
2254222845[RFC 3211]: https://datatracker.ietf.org/doc/html/rfc3211
@@ -22545,3 +22848,4 @@ ndif
2254522848[RFC 8446]: https://datatracker.ietf.org/doc/html/rfc8446
2254622849[RFC 8446 Section 4.6.1]: https://datatracker.ietf.org/doc/html/rfc8446#section-4.6.1
2254722850[RFC 8452]: https://datatracker.ietf.org/doc/html/rfc8452
22851+ [RFC 9000]: https://datatracker.ietf.org/doc/html/rfc9000
0 commit comments