OpenSSL 3.3.6
OpenSSL 3.3.6 is a security patch release. The most severe CVE fixed in this release is High.
This release incorporates the following bug fixes and mitigations:
-
Fixed Stack buffer overflow in CMS
AuthEnvelopedDataparsing. (CVE-2025-15467) -
Fixed NULL dereference in
SSL_CIPHER_find()function on unknown cipher ID. (CVE-2025-15468) -
Fixed TLS 1.3
CompressedCertificateexcessive memory allocation. (CVE-2025-66199)