Re: [EXTERNAL] New OpenSSL Releases

Tomas Mraz <[email protected]> Wed, 24 Sep 2025 09:28:06 +0200
Newsgroups gmane.comp.encryption.openssl.project,gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
Not really. The fixes for the security issues that will be released
with these upcoming versions are NOT present in the public github
repository of openssl. They will be merged only immediately before the
release is done.

We never merge fixes of issues with higher severity than Low to the
repository ahead of the release. And the security fixes always refer to
the CVE id of the fixed issue.

I would be interested to know which commit your colleague identified as
fixing a security issue. Most likely it is a fix for an issue that we
did not classify as security issue accoring to our security policy [1].
However if you reply to me privately with the concrete commit, I will
verify that there is no additional fix that should be classified as a
security issue.

[1]
https://openssl-library.org/policies/general/security-policy/index.html

Kind regards,

Tomáš Mráz, Public Support and Security Manager, OpenSSL Foundation


On Wed, 2025-09-24 at 06:45 +0000, Martin Bonner wrote:
> I forwarded the information internally, and a colleague asked for
> more details. I said there weren't any at the moment, and within 15
> minutes he had replied pointing at the commit that is almost
> certainly the cause of this release.  Given it is so easy to find, is
> there any point in being so coy about what the problem is?
> 
> Martin Bonner
> 
> 
> -----Original Message-----
> From: Tomas Mraz <[email protected]>
> Sent: 23 September 2025 14:57
> To: [email protected]; [email protected]
> Subject: [EXTERNAL] New OpenSSL Releases
> 
> The OpenSSL project team would like to announce the upcoming release
> of OpenSSL versions 3.5.4, 3.4.3, 3.3.5, 3.2.5 and 3.0.18.
> 
> We will be also releasing extended support OpenSSL versions 1.0.2zm
> and 1.1.1zd which will be available to premium support customers.
> 
> These releases will be made available on Tuesday 30th September 2025
> between 1300-1700 UTC.
> 
> These are security-fix releases. The highest severity issue fixed in
> each of these releases is Moderate:
> 
> https://openssl-library.org/policies/general/security-policy/index.html
> 
> Yours
> The OpenSSL Project Team
> 
> --
> You received this message because you are subscribed to the Google
> Groups "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it,
> send an email to [email protected].
> To view this discussion visit
> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/b6525571ac6bce35570fced2470872048a3af381.camel%40openssl.org
> .
> Any email and files/attachments transmitted with it are intended
> solely for the use of the individual or entity to whom they are
> addressed. If this message has been sent to you in error, you must
> not copy, distribute or disclose of the information it contains.
> Please notify Entrust immediately and delete the message from your
> system.
> 

-- 
Tomáš Mráz, Public Support and Security Manager, OpenSSL Foundation
Join the Code Protectors or support us on Github Sponsors
https://openssl-foundation.org/donate/

-- 
You received this message because you are subscribed to the Google Groups "openssl-project" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-project/2211c3f51b2aec212130ff7851b12b2beab01262.camel%40openssl.org.