OpenSSL 3.3.6 version showing critical vulnerability (CVE-2025-15467)

Raghu Chidambaram <[email protected]> Wed, 18 Mar 2026 11:23:40 -0700 (PDT)
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
------=_Part_43532_395644928.1773858220022
Content-Type: multipart/alternative; 
	boundary="----=_Part_43533_1740651132.1773858220022"

------=_Part_43533_1740651132.1773858220022
Content-Type: text/plain; charset="UTF-8"

Hi Team,

our application we are using OpenSSL 3.3.6 version, recently we upgraded 
from 3.3.5 to 3.3.6.

our blackduck tool is reporting one critical issue in this version for 
libssl library.

CVE - CVE-2025-15467

Till now when ever we take the OpenSSL version say x, both libssl and 
libcryto were showing same versions. but from OpenSSL 3.3.x onwards i m not 
sure why libssl shows different version and libcrypto shows different 
version. Why this discrepancy in the same OpenSSL code. Now because of this 
blackduck tool is showing critical issue in libssl.

so can you please provide some inputs on this on how to handle this case 

onefs-49-1# strings libcrypto.so.3 | grep "3.3.6"
OpenSSL 3.3.6 27 Jan 2026
* 3.3.6*
onefs-49-1# strings libssl.so.3 | grep "3.3.0"
OPENSSL*_3.3.0*

 onefs-49-1# openssl version

*OpenSSL 3.3.6 *27 Jan 2026 (Library: OpenSSL 3.3.6 27 Jan 2026)

CVE-2025-15467 critical

Thanks,

Raghavendra

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/5c6a2e7c-dbf7-438f-b68a-979474e88ef6n%40openssl.org.

------=_Part_43533_1740651132.1773858220022
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Team,<div><br /></div><div>our application we are using OpenSSL 3.3.6 ve=
rsion, recently we upgraded from 3.3.5 to 3.3.6.</div><div><br /></div><div=
>our blackduck tool is reporting one critical issue in this version for lib=
ssl library.</div><div><br /></div><div>CVE -=C2=A0CVE-2025-15467</div><div=
><br /></div><div>Till now when ever we take the OpenSSL version say x, bot=
h libssl and libcryto were showing same versions. but from OpenSSL 3.3.x on=
wards i m not sure why libssl shows different version and libcrypto shows d=
ifferent version. Why this discrepancy in the same OpenSSL code. Now becaus=
e of this blackduck tool is showing critical issue in libssl.</div><div><br=
 /></div><div>so can you please provide some inputs on this on how to handl=
e this case=C2=A0</div><div><br /></div><div><p>onefs-49-1# strings libcryp=
to.so.3 | grep "3.3.6"<br />
OpenSSL 3.3.6 27 Jan 2026<br /><b>
3.3.6</b><br />
onefs-49-1# strings libssl.so.3 | grep "3.3.0"<br />
OPENSSL<b>_3.3.0</b></p><p>=C2=A0onefs-49-1# openssl version</p><p><b>OpenS=
SL 3.3.6 </b>27 Jan 2026 (Library: OpenSSL 3.3.6 27 Jan 2026)</p><p>
CVE-2025-15467 critical</p><p>Thanks,</p><p>Raghavendra</p></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/a/openss=
l.org/d/msgid/openssl-users/5c6a2e7c-dbf7-438f-b68a-979474e88ef6n%40openssl=
.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/a/op=
enssl.org/d/msgid/openssl-users/5c6a2e7c-dbf7-438f-b68a-979474e88ef6n%40ope=
nssl.org</a>.<br />

------=_Part_43533_1740651132.1773858220022--

------=_Part_43532_395644928.1773858220022--