KEMBAR78
Release OpenSSL 3.4.1 · openssl/openssl · GitHub
Skip to content

OpenSSL 3.4.1

Choose a tag to compare

@openssl-machine openssl-machine released this 11 Feb 14:46
· 2517 commits to master since this release

OpenSSL 3.4.1 is a security patch release. The most severe CVE fixed in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (CVE-2024-12797)

  • Fixed timing side-channel in ECDSA signature computation. (CVE-2024-13176)