Skip to content
openSUSE OpenSSL 3 Important Fix Buffer Overflow 2026-3866

openSUSE OpenSSL 3 Important Fix Buffer Overflow 2026-3866

Linuxsecurity LinuxSecurity Advisories August 31, 2026

Find practical guidance for preventing, investigating, and responding to Linux security problems. Find practical guidance for preventing, investigating, and responding to Linux security problems. _ Review Linux Privileges ×

This update for openssl-3 fixes the following issues:

* CVE-2026-54874: excessive memory use when buffering DTLS records for a

future epoch (bsc#1274795).

* CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788).

* CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server

* CVE-2026-63076: invalid pointer dereference in the CMP server via crafted

`protectionAlg` (bsc#1274790).

* CVE-2026-75803: AEAD forgeries with empty ciphertext when using

`EVP_Cipher()` (bsc#1275837).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3866=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3866=1

zypper in -t patch SUSE-2026-3866=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)

* libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.64.1

* libopenssl3-32bit-3.1.4-150600.5.64.1

* libopenssl-3-fips-provider-32bit-3.1.4-150600.5.64.1

* libopenssl3-32bit-debuginfo-3.1.4-150600.5.64.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)

* openssl-3-3.1.4-150600.5.64.1

* libopenssl3-debuginfo-3.1.4-150600.5.64.1

* libopenssl-3-devel-3.1.4-150600.5.64.1

* libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.64.1

* libopenssl3-3.1.4-150600.5.64.1

* libopenssl-3-fips-provider-3.1.4-150600.5.64.1

* openssl-3-debugsource-3.1.4-150600.5.64.1

* openssl-3-debuginfo-3.1.4-150600.5.64.1

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* openssl-3-3.1.4-150600.5.64.1

* libopenssl3-debuginfo-3.1.4-150600.5.64.1

* libopenssl-3-devel-3.1.4-150600.5.64.1

* libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.64.1

* libopenssl3-3.1.4-150600.5.64.1

* libopenssl-3-fips-provider-3.1.4-150600.5.64.1

*

*

*

*

*

*

*

*

*

*

*

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases