Skip to content
Discussion options

You must be logged in to vote

OpenSSL 3.2 and 3.3 are affected by CVE-2026-42769 and the only possible reason they weren't patched is that both branches had already reached end-of-life before the advisory was published.

The affected API was added in commit 01b0485 ("CMP: add support for genm with rootCaCert and genp with rootCaKeyUpdate", July 2023). That commit first shipped in OpenSSL 3.2.0, so every 3.2.x and 3.3.x release contains the vulnerable code.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@filiagees
Comment options

Answer selected by filiagees
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants