A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libressl | Openbsd | * | 3.6.3 (excluding) |
Libressl | Openbsd | 3.7.0 (including) | 3.7.3 (excluding) |
Openbsd | Openbsd | 7.2 (including) | 7.2 (including) |
Openbsd | Openbsd | 7.3 (including) | 7.3 (including) |