OpenSSL 3.2

Fin de soporte

OpenSSL 3.2 es una versión estable, publicada el 23 de noviembre de 2023. Dejó de recibir parches de seguridad el 23 de noviembre de 2025. La última versión puntual publicada es la 3.2.6, del 30 de septiembre de 2025.

Avisos de seguridad

Seguimos 14 avisos que afectan a OpenSSL. Son los avisos del producto: no están filtrados por versión.

CVE-2026-35189 Media 5.3 2026-09-29

OpenSSL

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-54872 Baja 3.7 2026-09-29

OpenSSL

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-75805 Media 5.3 2026-09-29

OpenSSL

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-75806 Media 5.3 2026-09-29

OpenSSL

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-77696 Baja 3.7 2026-09-29

OpenSSL

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-84782 Alta 8.2 2026-09-29

OpenSSL

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

Ver los 14 avisos de OpenSSL

Fechas de endoflife.date, publicadas bajo licencia CC BY 4.0. Esta ficha se genera automáticamente y no sustituye al calendario oficial del proyecto; así se elabora la lista.

Si lo instalaste desde tu distribución, esta fecha no es la tuya

Estas son las fechas del proyecto original. Debian, Ubuntu y RHEL congelan una versión al publicar cada release y le retroportan los parches de seguridad durante todo el ciclo de la distribución, así que un paquete que aquí figura fuera de soporte puede seguir recibiendo correcciones por la vía de tu distribución. Lo que manda entonces es el calendario de la distribución.