﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
6033	openssl-4.0.3	Joe Locash	lfs-book	"{{{
### Major changes between OpenSSL 4.0.2 and OpenSSL 4.0.3 [29 Sep 2026]

OpenSSL 4.0.3 is a security patch release.  The most severe CVE fixed
in this release is High.

This release incorporates the following bug fixes and mitigations:

  * Fixed DTLS retransmissions of handshake messages from a stale buffer offset.
    ([CVE-2026-84782])

  * Fixed a use-after-free in X.509 extension cache under concurrent use.
    ([CVE-2026-84783])

  * Fixed excessive memory allocation in relative CRLDP processing.
    ([CVE-2026-35189])

  * Fixed QUIC unvalidated amplification credit may be over-accounted.
    ([CVE-2026-35191])

  * Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC.
    ([CVE-2026-42772])

  * Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves.
    ([CVE-2026-54872])

  * Fixed QUIC `STREAM` fragment metadata DoS.
    ([CVE-2026-54873])

  * Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V.
    ([CVE-2026-54875])

  * Fixed out-of-bounds access after `SSL_set_SSL_CTX()` during a handshake.
    ([CVE-2026-72897])

  * Fixed QUIC connection-level flow control was not enforced for streams.
    ([CVE-2026-75804])

  * Fixed a NULL pointer dereference in CMP client revocation response handling.
    ([CVE-2026-75805])

  * Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS.
    ([CVE-2026-75806])

  * Fixed a timing side-channel in SM2 signature generation.
    ([CVE-2026-77696])

  * Fixed an unbounded `RETIRE_CONNECTION_ID` backlog in QUIC stack
    implementation.
    ([CVE-2026-84784])

  * Fixed a bug where `EVP_DecryptFinal()` incorrectly reported a stale success
    on AES-SIV authentication failure.

  * Fixed a regression in base64 encoding BIO filter introduced in OpenSSL 4.0,
    where incomplete writes down the BIO chain may result in the loss of encoded
    base64 data.
}}}
"	enhancement	new	high	13.2	Book	git	major			
