OpenSSL 4.0.2 Patches 11 Vulnerabilities, Including Moderate QUIC Flaw
OpenSSL released version 4.0.2, addressing eleven vulnerabilities across its supported branches alongside parallel updates for OpenSSL 3.6, 3.5, 3.4, 3.0, and legacy 1.1.1 and 1.0.2 lines. The update patches a mix of Moderate and Low-severity issues, with the most critical finding being CVE-2026-18798, a Moderate-rated double-free flaw in the QUIC server that can trigger a denial of service. Other fixes target heap buffer overflows in CMS key unwrapping, memory amplification in DTLS record buffering, and format string vulnerabilities in the Certificate Management Protocol, all of which lack exploitable remote code execution paths. Administrators running OpenSSL 4.0.0 through 4.0.1 should upgrade to 4.0.2 immediately, while users on older branches must pull the corresponding point releases to resolve the disclosed resource management and integrity check issues.
OpenSSL 4.0.2 Patches 11 Vulnerabilities, Including Moderate QUIC Flaw @ Linux Compatible
OpenSSL 4.0.2 Patches 11 Vulnerabilities, Including Moderate QUIC Flaw
OpenSSL has released version 4.0.2, which addresses eleven vulnerabilities, including a moderate severity QUIC flaw that can lead to denial of service but does not allow for remote code execution. The update includes patches for multiple older versions of OpenSSL, with specific focus on issues such as heap buffer overflows and memory amplification. Notably, five of the vulnerabilities are related to the QUIC protocol, highlighting its ongoing development and the associated memory management challenges. Users are urged to upgrade to the latest version or corresponding point releases to mitigate these vulnerabilities and enhance security
