Base OpenSSL picks up a batch of memory and protocol bugs
Brief
15.x lists eight CVEs. 14.x lists four of them.
Notes
FreeBSD-SA-26:61.openssl. Vendor writeup: OpenSSL 2026-08-25.
15.x (OpenSSL 3.5): CVE-2026-14457, 18798, 54874, 63072, 63073, 63074, 63075, 63076. 14.x (OpenSSL 3.0): CVE-2026-54874, 63072, 63074, 63076. Do not invent which CVE is remote code execution. Do not invent CVSS.
releng/15.1 2fdcba9f607e. releng/15.0 ae2c9e5bba0a. releng/14.4 275b424d3cc2. stable/15 c5ad29cb6c62, stable/14 9e9609ab9c5c. Tags 15.1-p3 / 15.0-p13 / 14.4-p9 are this batch.
Commit 2fdcba9f607ee7e5c4987af75c5fc3005a3e3677