| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| openssl-3.6.5.tar.gz | < 19 hours ago | 55.1 MB | |
| openssl-3.6.5.tar.gz.asc | < 19 hours ago | 931 Bytes | |
| openssl-3.6.5.tar.gz.sha1 | < 19 hours ago | 63 Bytes | |
| openssl-3.6.5.tar.gz.sha256 | < 19 hours ago | 87 Bytes | |
| OpenSSL 3.6.5 source code.tar.gz | < 19 hours ago | 55.3 MB | |
| OpenSSL 3.6.5 source code.zip | < 19 hours ago | 59.0 MB | |
| README.md | < 19 hours ago | 2.7 kB | |
| Totals: 7 Items | 169.3 MB | 0 | |
OpenSSL 3.6.5 is a security patch release. The most severe CVE fixed in this release is High.
This release incorporates the following bug fixes and mitigations:
-
Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782)
-
Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189)
-
Fixed QUIC unvalidated amplification credit may be over-accounted. (CVE-2026-35191)
-
Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772)
-
Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872)
-
Fixed QUIC
STREAMfragment metadata DoS. (CVE-2026-54873) -
Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875)
-
Fixed out-of-bounds access after
SSL_set_SSL_CTX()during a handshake. (CVE-2026-72897) -
Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804)
-
Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805)
-
Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806)
-
Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696)
-
Fixed an unbounded
RETIRE_CONNECTION_IDbacklog in QUIC stack implementation. (CVE-2026-84784) -
Fixed a bug where
EVP_DecryptFinal()incorrectly reported a stale success on AES-SIV authentication failure.