OpenSSL 4.0.3 Fixes 15 Security Issues, With Updates for the 3.x Branches
The OpenSSL project released OpenSSL 4.0.3 on September 29, a security release fixing 15 issues. Maintenance releases for the older branches shipped at the same time: 3.6.5, 3.5.9, and 3.4.8.
Notable fixes
| CVE | Issue |
|---|---|
| CVE-2026-84783 | Use-after-free in the X.509 extension cache during concurrent operations |
| CVE-2026-42772 | CPU denial of service through O(n²) fragment reassembly in QUIC |
| CVE-2026-54872 | Timing side channel in scalar multiplication for non-NIST elliptic curves |
| CVE-2026-72897 | Out-of-bounds access after SSL_set_SSL_CTX() during a handshake |
| CVE-2026-75805 | NULL pointer dereference in CMP client revocation response handling |
Other fixes cover DTLS authentication, the QUIC implementation, SM2 signatures, and base64 encoding regressions introduced in 4.0.
The QUIC denial of service is the one most servers should care about: an attacker sending crafted fragments can make the reassembly code burn CPU, which is a cheap way to slow down an HTTP/3 or QUIC endpoint. The use-after-free matters most for multi-threaded applications that verify certificates concurrently.
Which branch are you on?
Most Linux distributions still ship an OpenSSL 3.x branch, and stable distributions backport fixes without changing the version. Check what you have:
openssl version
Then update through your package manager rather than building from source, and restart services that link OpenSSL. A library update does not reach running processes until they restart:
sudo apt update && sudo apt upgrade # Debian / Ubuntu
sudo dnf upgrade --refresh # Fedora / RHEL
# find processes still using the old library
sudo lsof -n | grep -E 'libssl.*(deleted)' | awk '{print $1}' | sort -u
needrestart on Debian and Ubuntu, or dnf needs-restarting -s on Fedora and RHEL, does the same check automatically. Our lsof guide explains the deleted-library trick, and shared libraries explained covers why restarts are needed.