OpenSSL 3.3.6 version showing critical vulnerability (CVE-2025-15467)
Raghu Chidambaram <[email protected]> Wed, 18 Mar 2026 11:23:40 -0700 (PDT)
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_43532_395644928.1773858220022 Content-Type: multipart/alternative; boundary="----=_Part_43533_1740651132.1773858220022" ------=_Part_43533_1740651132.1773858220022 Content-Type: text/plain; charset="UTF-8" Hi Team, our application we are using OpenSSL 3.3.6 version, recently we upgraded from 3.3.5 to 3.3.6. our blackduck tool is reporting one critical issue in this version for libssl library. CVE - CVE-2025-15467 Till now when ever we take the OpenSSL version say x, both libssl and libcryto were showing same versions. but from OpenSSL 3.3.x onwards i m not sure why libssl shows different version and libcrypto shows different version. Why this discrepancy in the same OpenSSL code. Now because of this blackduck tool is showing critical issue in libssl. so can you please provide some inputs on this on how to handle this case onefs-49-1# strings libcrypto.so.3 | grep "3.3.6" OpenSSL 3.3.6 27 Jan 2026 * 3.3.6* onefs-49-1# strings libssl.so.3 | grep "3.3.0" OPENSSL*_3.3.0* onefs-49-1# openssl version *OpenSSL 3.3.6 *27 Jan 2026 (Library: OpenSSL 3.3.6 27 Jan 2026) CVE-2025-15467 critical Thanks, Raghavendra -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/5c6a2e7c-dbf7-438f-b68a-979474e88ef6n%40openssl.org. ------=_Part_43533_1740651132.1773858220022 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Team,<div><br /></div><div>our application we are using OpenSSL 3.3.6 ve= rsion, recently we upgraded from 3.3.5 to 3.3.6.</div><div><br /></div><div= >our blackduck tool is reporting one critical issue in this version for lib= ssl library.</div><div><br /></div><div>CVE -=C2=A0CVE-2025-15467</div><div= ><br /></div><div>Till now when ever we take the OpenSSL version say x, bot= h libssl and libcryto were showing same versions. but from OpenSSL 3.3.x on= wards i m not sure why libssl shows different version and libcrypto shows d= ifferent version. Why this discrepancy in the same OpenSSL code. Now becaus= e of this blackduck tool is showing critical issue in libssl.</div><div><br= /></div><div>so can you please provide some inputs on this on how to handl= e this case=C2=A0</div><div><br /></div><div><p>onefs-49-1# strings libcryp= to.so.3 | grep "3.3.6"<br /> OpenSSL 3.3.6 27 Jan 2026<br /><b> 3.3.6</b><br /> onefs-49-1# strings libssl.so.3 | grep "3.3.0"<br /> OPENSSL<b>_3.3.0</b></p><p>=C2=A0onefs-49-1# openssl version</p><p><b>OpenS= SL 3.3.6 </b>27 Jan 2026 (Library: OpenSSL 3.3.6 27 Jan 2026)</p><p> CVE-2025-15467 critical</p><p>Thanks,</p><p>Raghavendra</p></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/a/openss= l.org/d/msgid/openssl-users/5c6a2e7c-dbf7-438f-b68a-979474e88ef6n%40openssl= .org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/a/op= enssl.org/d/msgid/openssl-users/5c6a2e7c-dbf7-438f-b68a-979474e88ef6n%40ope= nssl.org</a>.<br /> ------=_Part_43533_1740651132.1773858220022-- ------=_Part_43532_395644928.1773858220022--