{"id":144089,"date":"2025-10-03T17:12:04","date_gmt":"2025-10-03T15:12:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-openssl-3-6-0-s-podderzhkoj-evp_skey-i-ustraneniem-perepolneniya-bufera"},"modified":"2025-10-03T17:12:04","modified_gmt":"2025-10-03T15:12:04","slug":"vypusk-openssl-3-6-0-s-podderzhkoj-evp_skey-i-ustraneniem-perepolneniya-bufera","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-openssl-3-6-0-s-podderzhkoj-evp_skey-i-ustraneniem-perepolneniya-bufera","title":{"rendered":"Release of OpenSSL 3.6.0 with EVP_SKEY support and buffer overflow fixes","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The release of OpenSSL 3.6.0 has occurred, offering the implementation of SSL\/TLS protocols and various encryption algorithms. OpenSSL 3.6 is classified as a standard-support release, with updates being issued for 13 months. Support for previous branches OpenSSL 3.5 LTS, 3.4, 3.3, 3.2, and 3.0 LTS will last until April 2030, October 2026, April 2026, November 2025, and September 2026, respectively. The project's code is distributed under the Apache 2.0 license.     <\/p>\n<p>Key innovations:   <\/p>\n<ul>\n<li class=\"l\"> Support for the EVP_SKEY structure (Symmetric KEY) has been added to represent symmetric keys as opaque objects. Unlike raw keys represented as byte arrays, the EVP_SKEY structure abstracts the key and contains additional metadata. Usage of EVP_SKEY is permitted in encryption functions, key exchange, and key derivation functions (KDF). Functions EVP_KDF_CTX_set_SKEY(), EVP_KDF_derive_SKEY(), and EVP_PKEY_derive_SKEY() have been added for working with EVP_SKEY keys.\n<li class=\"l\"> Support for digital signature verification based on the LMS (Leighton-Micali Signatures) scheme has been added, utilizing hash functions and tree hashing in the form of a Merkle Tree (each branch verifies all underlying branches and nodes). LMS digital signatures are resistant to key search on quantum computers and are designed to ensure the integrity of firmware and applications.\n<li class=\"l\"> Support for NIST security categories has been added for PKEY object parameters (both public and private keys). The security category is set through the \"security-category\" configuration. The function EVP_PKEY_get_security_category() has been added to check the security level. The security level reflects resistance to attacks by quantum computers and can take integer values from 0 to 5:\n<ul>\n<li class=\"l\"> 0 \u2014 implementation that is not resistant to attacks by quantum computers;\n<li class=\"l\">  1\/3\/5 \u2014 implementation does not rule out the search for a key by a quantum computer in a block cipher with a 128\/192\/256-bit key;\n<li class=\"l\">  2\/4 \u2014 implementation does not rule out the search for collisions in a 256\/384-bit hash by a quantum computer).   <\/ul>\n<li class=\"l\"> The command \"openssl configutl\" has been added for processing the configuration file. The utility allows the creation of a consolidated file with all settings based on a multi-file configuration with include directives.\n<li class=\"l\"> The FIPS cryptoprovider now supports deterministic generation of ECDSA digital signatures (the same signature is generated for the same inputs), in accordance with the requirements of the FIPS 186-5 standard.\n<li class=\"l\"> The requirements for the build environment have been raised. It is no longer sufficient to have ANSI-C compliant tools for building OpenSSL; a compiler compatible with the C-99 standard is now required.\n<li class=\"l\"> Functions related to the EVP_PKEY_ASN1_METHOD structure have been deprecated.\n<li class=\"l\"> Support for the VxWorks platform has been discontinued.                  <\/ul>\n<p>Fixed vulnerabilities:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2025-9230 \u2014 a vulnerability in the code for decrypting CMS messages encrypted using a password (PWRI). This vulnerability can lead to writing and reading data outside the allocated buffer, potentially causing a crash or memory corruption in applications using OpenSSL to process CMS messages. Exploitation of this vulnerability might allow for arbitrary code execution, but the risk is mitigated by the fact that CMS message encryption using a password is very rarely used in practice. In addition to OpenSSL version 3.6.0, the vulnerability has been fixed in releases 3.5.4, 3.4.3, 3.3.5, 3.2.6, and 3.0.18. The issue is also resolved in library updates LibreSSL 4.0.1 and 4.1.1, maintained by the OpenBSD project.\n<li class=\"l\"> CVE-2025-9231 \u2014 the implementation of the SM2 algorithm is vulnerable to side-channel attacks, allowing the recreation of the private key on systems with 64-bit ARM CPUs by analyzing execution time variations of individual computations. The attack can potentially be carried out remotely. The risk of this attack is lowered since OpenSSL does not directly support the use of certificates with SM2 keys in TLS.\n<li class=\"l\"> CVE-2025-9232 \u2014 a vulnerability in the implementation of the built-in HTTP client that allows reading data from out-of-bounds memory when handling specially formatted URLs in HTTP Client functions. The issue occurs only when the environment variable \"no_proxy\" is set and may lead to application crashes.           <\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63979\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.6.0, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u0439 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 SSL\/TLS \u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. OpenSSL 3.6 \u043e\u0442\u043d\u0435\u0441\u0451\u043d \u043a \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u043c \u0441 \u043e\u0431\u044b\u0447\u043d\u044b\u043c \u0441\u0440\u043e\u043a\u043e\u043c \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438, \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u044e\u0442\u0441\u044f \u0432 \u0442\u0435\u0447\u0435\u043d\u0438\u0435 13 \u043c\u0435\u0441\u044f\u0446\u0435\u0432. \u041f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u043f\u0440\u043e\u0448\u043b\u044b\u0445 \u0432\u0435\u0442\u043e\u043a OpenSSL 3.5 LTS, 3.4, 3.3, 3.2 \u0438 3.0 LTS \u043f\u0440\u043e\u0434\u043b\u0438\u0442\u0441\u044f \u0434\u043e \u0430\u043f\u0440\u0435\u043b\u044f 2030 \u0433\u043e\u0434\u0430, \u043e\u043a\u0442\u044f\u0431\u0440\u044f 2026 \u0433\u043e\u0434\u0430, \u0430\u043f\u0440\u0435\u043b\u044f 2026 \u0433\u043e\u0434\u0430, \u043d\u043e\u044f\u0431\u0440\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-144089","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.6.0, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u0439 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 SSL\/TLS \u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-openssl-3-6-0-s-podderzhkoj-evp_skey-i-ustraneniem-perepolneniya-bufera\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a OpenSSL 3.6.0 \u0441 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u043e\u0439 EVP_SKEY \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0431\u0443\u0444\u0435\u0440\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.6.0, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u0439 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 SSL\/TLS \u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-openssl-3-6-0-s-podderzhkoj-evp_skey-i-ustraneniem-perepolneniya-bufera\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-10-03T15:12:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-10-03T15:12:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 OpenSSL 3.6.0 release with EVP_SKEY support and buffer overflow fixes | ProHoster","description":"The release of OpenSSL 3.6.0 has occurred, offering the implementation of SSL\/TLS protocols and various encryption algorithms.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-openssl-3-6-0-s-podderzhkoj-evp_skey-i-ustraneniem-perepolneniya-bufera","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a OpenSSL 3.6.0 \u0441 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u043e\u0439 EVP_SKEY \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0431\u0443\u0444\u0435\u0440\u0430 | ProHoster","og:description":"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.6.0, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u0439 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 SSL\/TLS \u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-openssl-3-6-0-s-podderzhkoj-evp_skey-i-ustraneniem-perepolneniya-bufera","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-10-03T15:12:04+00:00","article:modified_time":"2025-10-03T15:12:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"144089","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 15:06:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 15:06:19","updated":"2026-01-23 15:06:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/144089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=144089"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/144089\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=144089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=144089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=144089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}