OpenSSL 4.0.3 Releases 14 Security Fixes Across QUIC, DTLS and SM2

Published by

OpenSSL 4.0.3 has been released, addressing 14 vulnerabilities related to QUIC, DTLS, X.509 certificate handling, and the SM2 cryptographic suite, with the most severe flaw rated as High. Notable issues include an AES-SIV authentication error that could misreport tampered data and a base64 encoding bug that may lead to truncated output. The release highlights significant themes, particularly the prevalence of QUIC vulnerabilities and recurring timing side-channel issues in cryptographic operations. OpenSSL is rapidly evolving, with a final release of version 4.1 expected soon, which will include DTLS 1.3 support and a commitment to regular major updates every two years



OpenSSL 4.0.3 Releases 14 Security Fixes Across QUIC, DTLS and SM2

OpenSSL 4.0.3 shipped today, closing 14 vulnerabilities spanning the QUIC transport, DTLS, X.509 certificate handling, the SM2 cryptographic suite and core key-management code. The project rated its worst flaw High, yet two unnumbered bugs deserve attention: an AES-SIV authentication misreporting error that could mask tampered data, and a base64 BIO regression that might silently truncate output. Reading the fixes together reveals the themes of the release, with QUIC accounting for at least five of the CVEs and a cluster of timing side channels targeting SM2 on ARM64 and RISC-V. Timing matters because OpenSSL 4.1 is nearly here—Beta1 landed September 23 with a final release expected in October and DTLS 1.3 support—while OpenSSL 3.0 already reached end of life on September 16.

OpenSSL 4.0.3 Releases 14 Security Fixes Across QUIC, DTLS and SM2 @ Linux Compatible