This update for openssl-3 fixes the following issues
- CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652).
- CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340).
- CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341).
- CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342).
- CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344).
- CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345).
- CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347).
- CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349).
- CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350).
- CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351).
-...
Read the Full Advisory- openSUSE Leap 16.0:
libopenssl-3-devel-3.5.0-160000.8.1
libopenssl-3-fips-provider-3.5.0-160000.8.1
libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.8.1
libopenssl3-3.5.0-160000.8.1
libopenssl3-x86-64-v3-3.5.0-160000.8.1
openssl-3-3.5.0-160000.8.1
openssl-3-doc-3.5.0-160000.8.1
* bsc#1259652
* bsc#1266340
* bsc#1266341
* bsc#1266342
* bsc#1266344
* bsc#1266345
* bsc#1266347
* bsc#1266349
* bsc#1266350
* bsc#1266351
* bsc#1266352
* bsc#1266353
* bsc#1266355
* bsc#1266356
* bsc#1266357
References:
* https://www.suse.com/security/cve/CVE-2026-2673.html
* https://www.suse.com/security/cve/CVE-2026-34180.html
* https://www.suse.com/security/cve/CVE-2026-34182.html
* https://www.suse.com/security/cve/CVE-2026-34183.html
* https://www.suse.com/security/cve/CVE-2026-42764.html
* https://www.suse.com/security/cve/CVE-2026-42766.html
* https://www.suse.com/security/cve/CVE-2026-42767.html
* https://www.suse.com/security/cve/CVE-2026-42768.html
* https://www.suse.com/security/cve/CVE-2026-42769.html
* https://www.suse.com/security/cve/CVE-2026-42770.html
* https://www.suse.com/security/cve/CVE-2026-45445.html
* https://www.suse.com/security/cve/CVE-2026-45446.html
* https://www.suse.com/security/cve/CVE-2026-45447.html
* https://www.suse.com/security/cve/CVE-2026-7383.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.