FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- Multiple vulnerabilities in OpenSSL

Affected packages
15.0 <= FreeBSD < 15.0_10
14.4 <= FreeBSD < 14.4_6
14.3 <= FreeBSD < 14.3_15

Details

VuXML ID a57fe2c1-6476-11f1-958d-bc241121aa0a
Discovery 2026-06-09
Entry 2026-06-10

Problem Description:

Multiple issues have been reported as part of this advisory with different issues affecting different OpenSSL versions and therefore different FreeBSD versions. Instead of exhaustively listing detailed writeups for each issue, please see the referenced advisory from OpenSSL.

Issues affecting FreeBSD 15.x (OpenSSL 3.5):

Issues affecting FreeBSD 14.x (OpenSSL 3.0):

Impact:

The issues include heap buffer overflows and over-reads, NULL pointer dereferences, a use-after-free, unbounded memory allocation, and several cryptographic flaws permitting message forgery, integrity bypass, or recovery of a private key.

Security impact ranges from a Denial of Service to a potential remote code execution. See the OpenSSL advisory for specific details.

References

CVE Name CVE-2026-34180
CVE Name CVE-2026-34181
CVE Name CVE-2026-34182
CVE Name CVE-2026-34183
CVE Name CVE-2026-42764
CVE Name CVE-2026-42766
CVE Name CVE-2026-42767
CVE Name CVE-2026-42768
CVE Name CVE-2026-42769
CVE Name CVE-2026-42770
CVE Name CVE-2026-45445
CVE Name CVE-2026-45446
CVE Name CVE-2026-45447
CVE Name CVE-2026-7383
CVE Name CVE-2026-9076
FreeBSD Advisory SA-26:35.openssl