Last Updated: 2022-11-01 14:30:42 UTC
by Johannes Ullrich (Version: 1)
Some here may still remember Heartbleed. Heartbleed was a critical OpenSSL vulnerability that surprised many organizations, and patching the issue was a major undertaking. Heartbleed caused OpenSSL and other open-source projects to rethink how they address security issues and communicate with their users. OpenSSL started to pre-announce any security updates about a week ahead of time.
This week, OpenSSL announced they would release OpenSSL 3.0.7 this coming Tuesday. It will fix a critical vulnerability . The OpenSSL definition of critical:
- CRITICAL Severity. This affects common configurations and which are also likely to be exploitable. Examples include significant disclosure of the contents of server memory (potentially revealing user details), vulnerabilities which can be easily exploited remotely to compromise server private keys or where remote code execution is considered likely in common situations. These issues will be kept private and will trigger a new release of all supported versions. We will attempt to address these as soon as possible.
In short: This is something you will need to worry about!
The update will only affect OpenSSL 3.0.x, not 1.1.1. Now is the time to figure out where and how you are using OpenSSL 3.0.x. For most systems, you will be able to use the openssl command line utility:
% openssl version
OpenSSL 3.0.5 5 Jul 2022 (Library: OpenSSL 3.0.5 5 Jul 2022)
Here is a quick list of OpenSSL versions for different operating systems:
OpenSSL 3.0.0, the first stable version of OpenSSL 3.0, was released in September 2021, about one year ago. Any older operating systems are likely using OpenSSL 1.1.1, which is not affected.
macOS: macOS, by default, uses LibreSSL, not openssl, installed. But openssl may be installed later by other software like Homebrew and MacPorts.
[thanks to all the contributors to this table. Let me know if you have additional entries]
|Linux Distro||OpenSSL Version|
|CentOS Linux release 7.9||1.0.2|
|CentOS Stream 9||(3.0.1)|
|Debian 11 (bullseye)||(1.1.1)|
|Linux Mint 21 Vanessa||(3.0.2)|
|OpenSuSE Leap 15.2||(1.1.1)|
|OpenSuSE Leap 15.3||(1.1.1)|
|OpenSuSE Leap 15.4||(1.1.1)|
|Redhat EL 9||3.0|
|Rocky Linux release 9.0 (Blue Onyx)||3.0.1|
|Unifi Cloudkey 2.5.11||1.1.0|