The OpenBSD project has released a portable edition of the LibreSSL 3.2.5 package, which develops a fork of OpenSSL aimed at providing a higher level of security. The new version fixes a bug in the TLS client implementation that leads to accessing a freed memory block (use-after-free) during session resume operations. OpenBSD developers acknowledged that the bug leads to a vulnerability but refrained from publishing details, providing only the patch. There is currently no information regarding the possibility of a remote attack being organized. It is not ruled out that the vulnerability is related to an issue that caused crashes, which the haproxy project developers warned about in February.
Source: opennet.ru