Re: OpenSSL 3.3.6 version showing critical vulnerability (CVE-2025-15467)
"'Tomas Mraz' via openssl-users" <[email protected]> Fri, 20 Mar 2026 13:53:28 +0100
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <5f9d6f94ef55ddb03e4a269b45d47c442eb92e23.camel@openssl.foundation> |
As mentioned in https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467 and https://openssl-library.org/news/secadv/20260127.txt The issue is fixed in version 3.3.6. You need to report a bug by the vendor of the security scanner tool. Tomas Mraz, CTO, OpenSSL Foundation On Fri, 2026-03-20 at 05:27 -0700, Raghu Chidambaram wrote: > Thanks a lot for the information Tomas,=C2=A0 then i m not very sure why > our tool was showing two versions from 3.3.x versions onwards > previously when we were in 3.1.x there were no issues. >=20 > it will show as shown below so then we got confused and searching the > libssl.so with strings command. Then we found this version as 3.3.0 >=20 > so if you say that libssl doesn't have any affect then we will update > manually in the tool . >=20 > The fix for CVE-2026-15467 is solely applying to > libcrypto.so.3=C2=A0 > so for the above issue we need to migrate to 3.3.7 or something? or > it is already fixed in 3.3.6? >=20 > Thanks >=20 > On Thursday, 19 March 2026 at 13:54:51 UTC+5:30 Tomas Mraz wrote: > > Hello Raghu, > >=20 > > There are multiple problems with your tool. > >=20 > > 1. It is misidentifying the version of libssl. Please note that the > > presence of OPENSSL_3.3.0 in the version table of libssl.so.3 does > > NOT > > indicate that libssl is from the 3.3.0 release. > >=20 > > 2. (This is less of a problem of the tool as the tool might have > > hard > > time to know.) The fix for CVE-2026-15467 is solely applying to > > libcrypto.so.3, there is no change in libssl.so.3 in regards to > > this > > issue. > >=20 > > I do not think this has ever changed. libssl AFAIK never contained > > a > > full OpenSSL version string. If you want, you can suggest an > > enhancement in our public GitHub repository that we should include > > a > > full version string not just in libcrypto but also in libssl. > >=20 > > Kind regards, > >=20 > > Tomas Mraz, CTO, OpenSSL Foundation > >=20 > >=20 > > On Wed, 2026-03-18 at 11:23 -0700, Raghu Chidambaram wrote: > > > Hi Team, > > >=20 > > > our application we are using OpenSSL 3.3.6 version, recently we > > > upgraded from 3.3.5 to 3.3.6. > > >=20 > > > our blackduck tool is reporting one critical issue in this > > > version > > > for libssl library. > > >=20 > > > CVE -=C2=A0CVE-2025-15467 > > >=20 > > > Till now when ever we take the OpenSSL version say x, both libssl > > > and > > > libcryto were showing same versions. but from OpenSSL 3.3.x > > > onwards i > > > m not sure why libssl shows different version and libcrypto shows > > > different version. Why this discrepancy in the same OpenSSL code. > > > Now > > > because of this blackduck tool is showing critical issue in > > > libssl. > > >=20 > > > so can you please provide some inputs on this on how to handle > > > this > > > case=C2=A0 > > >=20 > > > onefs-49-1# strings libcrypto.so.3 | grep "3.3.6" > > > OpenSSL 3.3.6 27 Jan 2026 > > > 3.3.6 > > > onefs-49-1# strings libssl.so.3 | grep "3.3.0" > > > OPENSSL_3.3.0 > > > =C2=A0onefs-49-1# openssl version > > > OpenSSL 3.3.6 27 Jan 2026 (Library: OpenSSL 3.3.6 27 Jan 2026) > > > CVE-2025-15467 critical > > > Thanks, > > > Raghavendra > > > --=20 > > > You received this message because you are subscribed to the > > > Google > > > Groups "openssl-users" group. > > > To unsubscribe from this group and stop receiving emails from it, > > > send an email to [email protected] > > > To view this discussion visit > > > https://groups.google.com/a/openssl.org/d/msgid/openssl-users/5c6a2e7= c-dbf7-438f-b68a-979474e88ef6n%40openssl.org > >=20 > >=20 > > > . > >=20 --=20 Tom=C3=A1=C5=A1 Mr=C3=A1z, Chief Technology Officer, OpenSSL Foundation We need your support! Help us protect digital privacy=E2=80=A6 everywhere. https://openssl.foundation/donate/ways-to-give --=20 You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/5f9d6f94ef55ddb03e4a269b45d47c442eb92e23.camel%40openssl.f= oundation.