OpenSSL 3.0

Menos de seis meses

OpenSSL 3.0 es una versión LTS, publicada el 7 de septiembre de 2021. Recibe parches de seguridad hasta el 7 de septiembre de 2026. La última versión puntual publicada es la 3.0.22, del 25 de agosto de 2026.

Avisos de seguridad

Seguimos 8 avisos que afectan a OpenSSL. Son los avisos del producto: no están filtrados por versión.

CVE-2026-14456 Sin clasificar 2026-08-25

OpenSSL

openssl vulnerabilities

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-54874 Alta 7.5 2026-08-25

OpenSSL

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-63072 Alta 7.5 2026-08-25

OpenSSL

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-63074 Media 5.9 2026-08-25

OpenSSL

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-63076 Alta 7.5 2026-08-25

OpenSSL

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-75803 Sin clasificar 2026-08-25

OpenSSL

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

Ver los 8 avisos de OpenSSL

Fechas de endoflife.date, publicadas bajo licencia CC BY 4.0. Esta ficha se genera automáticamente y no sustituye al calendario oficial del proyecto; así se elabora la lista.

Si lo instalaste desde tu distribución, esta fecha no es la tuya

Estas son las fechas del proyecto original. Debian, Ubuntu y RHEL congelan una versión al publicar cada release y le retroportan los parches de seguridad durante todo el ciclo de la distribución, así que un paquete que aquí figura fuera de soporte puede seguir recibiendo correcciones por la vía de tu distribución. Lo que manda entonces es el calendario de la distribución.