OpenSSL 3.6.0 ืืจื•ื™ืกื’ืขื’ืขื‘ืŸ ืžื™ื˜ EVP_SKEY ืฉื˜ื™ืฆืข ืื•ืŸ ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืคื™ืงืก

OpenSSL 3.6.0, ืืŸ ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ SSL/TLS ืคืจืื˜ืืงืืœืŸ ืื•ืŸ ืคืืจืฉื™ื“ืขื ืข ืขื ืงืจื™ืคึผืฉืึทืŸ ืืœื’ืืจื™ื˜ืžืขืŸ, ืื™ื– ืืจื•ื™ืกื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ. OpenSSL 3.6 ืื™ื– ื ืจืขื’ื•ืœืขืจืข ืฉื˜ื™ืฆืข ืื•ื™ืกื’ืื‘ืข, ืžื™ื˜ ืืคื“ืขื™ื˜ืก ืคืืจืืŸ ืคืืจ 13 ื—ื“ืฉื™ื. ืฉื˜ื™ืฆืข ืคืืจ ืคืจื™ืขืจื“ื™ื’ืข OpenSSL ืื•ื™ืกื’ืื‘ืขืกโ€”3.5 LTS, 3.4, 3.3, 3.2, ืื•ืŸ 3.0 LTSโ€”ื•ื•ืขื˜ ืื ื’ื™ื™ืŸ ื‘ื™ื– ืืคืจื™ืœ 2030, ืืงื˜ืื‘ืขืจ 2026, ืืคืจื™ืœ 2026, ื ืื•ื•ืขืžื‘ืขืจ 2025, ืื•ืŸ ืกืขืคื˜ืขืžื‘ืขืจ 2026, ื‘ื”ืชืืžื”. ื“ืขืจ ืคืจืื™ืขืงื˜'ืก ืงืื•ื“ ืื™ื– ืœื™ื™ืกืขื ืกื˜ ืื•ื ื˜ืขืจ ื“ืขืจ Apache 2.0 ืœื™ื™ืกืขื ืก.

ื”ื•ื™ืคึผื˜ ื—ื™ื“ื•ืฉื™ื:

  • ืฆื•ื’ืขื’ืขื‘ืŸ ืฉื˜ื™ืฆืข ืคืืจ ื“ืขืจ EVP_SKEY (ืกื™ืžืขื˜ืจื™ืฉืขืจ KEY) ืกื˜ืจื•ืงื˜ื•ืจ ืคืืจืŸ ืจืขืคืจืขื–ืขื ื˜ื™ืจืŸ ืกื™ืžืขื˜ืจื™ืฉืข ืฉืœื™ืกืœืขืŸ ื•ื•ื™ ืื•ืžื“ื•ืจื›ื–ื™ื›ื˜ื™ืงืข ืื‘ื™ืขืงื˜ืŸ. ืื ื“ืขืจืฉ ื•ื•ื™ ืจื•ื™ืข ืฉืœื™ืกืœืขืŸ, ื•ื•ืขืœื›ืข ื•ื•ืขืจืŸ ืจืขืคืจืขื–ืขื ื˜ื™ืจื˜ ื•ื•ื™ ื ื‘ื™ื™ื˜ ืขืจืขื™, ืื‘ืกื˜ืจืืงื˜ื™ืจื˜ EVP_SKEY ื“ื™ ืฉืœื™ืกืœ ืกื˜ืจื•ืงื˜ื•ืจ ืื•ืŸ ืื ื˜ื”ืืœื˜ ื ืึธืš ืžืขื˜ืื“ืื˜ืŸ. EVP_SKEY ืงืขืŸ ื’ืขื ื•ืฆื˜ ื•ื•ืขืจืŸ ืื™ืŸ ืขื ืงืจื™ืคึผืฉืึทืŸ, ืฉืœื™ืกืœ ืื•ื™ืกื˜ื•ื™ืฉ, ืื•ืŸ ืฉืœื™ืกืœ ื“ืขืจื™ื•ื•ืึทืฆื™ืข (KDF) ืคื•ื ืงืฆื™ืขืก. ื“ื™ EVP_KDF_CTX_set_SKEY(), EVP_KDF_derive_SKEY(), ืื•ืŸ EVP_PKEY_derive_SKEY() ืคื•ื ืงืฆื™ืขืก ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ ืคืืจืŸ ืืจื‘ืขื˜ืŸ ืžื™ื˜ EVP_SKEY ืฉืœื™ืกืœืขืŸ.
  • ืฉื˜ื™ืฆืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืคึฟืึทืจ ื“ื™ื’ื™ื˜ืึทืœืข ืื•ื ื˜ืขืจืฉืจื™ืคึฟื˜ ื•ื•ืขืจื™ืคึฟื™ืงืึทืฆื™ืข ื‘ืึทื–ื™ืจื˜ ืื•ื™ืฃ ื“ืขืจ ืœื™ื™ื˜ืึธืŸ-ืžื™ืงืึทืœื™ ืกื™ื’ื ืึทื˜ืฉืขืจื– (LMS) ืกื›ืขืžืข, ื•ื•ืึธืก ื ื™ืฆื˜ ื”ืึทืฉ ืคึฟื•ื ืงืฆื™ืขืก ืื•ืŸ ื‘ื•ื™ื-ื‘ืึทื–ื™ืจื˜ ื”ืึทืฉื™ื ื’ ืื™ืŸ ื“ืขืจ ืคึฟืึธืจืขื ืคึฟื•ืŸ ืึท ืžืขืจืงืœ ื‘ื•ื™ื (ื™ืขื“ืขืจ ืฆื•ื•ื™ื™ึทื’ ื•ื•ืขืจื™ืคึฟื™ืฆื™ืจื˜ ืึทืœืข ืื•ื ื˜ืขืจืœื™ื™ื’ื ื“ื™ืงืข ืฆื•ื•ื™ื™ื’ืŸ ืื•ืŸ ื ืึธื•ื“ื–). LMS ื“ื™ื’ื™ื˜ืึทืœืข ืกื™ื’ื ืึทื˜ืฉืขืจื– ื–ืขื ืขืŸ ืงืขื’ื ืฉื˜ืขืœื™ืง ืฆื• ื‘ืจื•ื˜-ืคึฟืึธืจืก ื˜ืขืกื˜ื™ื ื’ ืื•ื™ืฃ ืึท ืงื•ื•ืึทื ื˜ื•ื ืงืึธืžืคึผื™ื•ื˜ืขืจ ืื•ืŸ ื–ืขื ืขืŸ ื“ื™ื–ื™ื™ื ื“ ืฆื• ื•ื•ืขืจื™ืคึฟื™ืฆื™ืจืŸ ื“ื™ ืึธืจื ื˜ืœืขื›ืงื™ื™ื˜ ืคึฟื•ืŸ ืคึฟื™ืจืžื•ื•ืขืจ ืื•ืŸ ืึทืคึผืœื™ืงืึทืฆื™ืขืก.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืฉื˜ื™ืฆืข ืคืืจ NIST ื–ื™ื›ืขืจื”ื™ื™ื˜ ืงืื˜ืขื’ืืจื™ืขืก ืคืืจ PKEY ืื‘ื™ืขืงื˜ ืคืืจืืžืขื˜ืขืจืก (ืคื•ื‘ืœื™ืง ืื•ืŸ ืคืจื™ื•ื•ืื˜ืข ืฉืœื™ืกืœืขืŸ). ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืงืื˜ืขื’ืืจื™ืข ื•ื•ืขืจื˜ ืื™ื™ื ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ื™ "ื–ื™ื›ืขืจื”ื™ื™ื˜-ืงืื˜ืขื’ืืจื™ืข" ืกืขื˜ื™ื ื’. ื“ื™ EVP_PKEY_get_security_category() ืคื•ื ืงืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ ืฆื• ืงืื ื˜ืจืืœื™ืจืŸ ื“ืขื ื–ื™ื›ืขืจื”ื™ื™ื˜ ืœืขื•ื•ืขืœ. ื“ืขืจ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืœืขื•ื•ืขืœ ืฉืคื™ื’ืœื˜ ืืค ื“ื™ ืงืขื’ื ืฉื˜ืื ื“ ืฆื• ื‘ืจื•ื˜-ืคืืจืก ืื˜ืืงืขืก ืื•ื™ืฃ ืงื•ื•ืื ื˜ื•ื ืงืืžืคื™ื•ื˜ืขืจืก ืื•ืŸ ืงืขืŸ ื ืขืžืขืŸ ื’ืื ืฆืข ื•ื•ืขืจื˜ืŸ ืคื•ืŸ 0 ื‘ื™ื– 5:
    • 0 - ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข ื ื™ืฉื˜ ืงืขื’ื ืฉื˜ืขืœื™ืง ืฆื• ื›ืึทืงื™ื ื’ ืื•ื™ืฃ ืงื•ื•ืึทื ื˜ื•ื ืงืึธืžืคึผื™ื•ื˜ืขืจืก;
    • 1/3/5 โ€” ื“ื™ ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข ืฉืœื™ืกื˜ ื ื™ืฉื˜ ืื•ื™ืก ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ื–ื•ื›ืŸ ื ืฉืœื™ืกืœ ืื™ืŸ ื ื‘ืœืืง-ืฆื™ืคืขืจ ืžื™ื˜ ื 128/192/256-ื‘ื™ื˜ ืฉืœื™ืกืœ ืื•ื™ืฃ ื ืงื•ื•ืื ื˜ื•ื ืงืืžืคื™ื•ื˜ืขืจ;
    • 2/4 - ื“ื™ ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข ืฉืœื™ืกื˜ ื ื™ืฉื˜ ืื•ื™ืก ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ื–ื•ื›ืŸ ื ืงืืœื™ื–ื™ืข ืื™ืŸ ื 256/384-ื‘ื™ื˜ ื”ืขืฉ ืื•ื™ืฃ ื ืงื•ื•ืื ื˜ื•ื ืงืืžืคื™ื•ื˜ืขืจ).
  • ื“ืขืจ "openssl configutl" ื‘ืึทืคึฟืขืœ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืคึฟืึทืจืŸ ืคึผืจืึธืฆืขืกื™ืจืŸ ืงืึธื ืคึฟื™ื’ื•ืจืึทืฆื™ืข ื˜ืขืงืขืก. ื“ื™ ื ื•ืฆืœืขื›ืงื™ื™ื˜ ื“ืขืจืžืขื’ืœืขื›ื˜ ืืฒึทืš ืฆื• ืฉืึทืคึฟืŸ ืึท ืงืึธื ืกืึธืœื™ื“ื™ืจื˜ืข ื˜ืขืงืข ืžื™ื˜ ืึทืœืข ืกืขื˜ื˜ื™ื ื’ืก ืคึฟื•ืŸ ืึท ืงืึธื ืคึฟื™ื’ื•ืจืึทืฆื™ืข ืคึฟื•ืŸ ืงื™ื™ืคืœ ื˜ืขืงืขืก ืžื™ื˜ includes.
  • ื“ืขืจ FIPS ืงืจื™ืคึผื˜ืึธื’ืจืึทืคึฟื™ืฉืขืจ ืคึผืจืึธื•ื•ืฒึทื“ืขืจ ืื™ื– ื’ืขื•ื•ืึธืจืŸ ืึทืคึผื“ื™ื™ื˜ืขื“ ืฆื• ืฉื˜ื™ืฆืŸ ื“ืขื˜ืขืจืžื™ื ื™ืกื˜ื™ืฉืข ื“ื–ืฉืขื ืขืจื™ื™ืฉืึทืŸ ืคึฟื•ืŸ ECDSA ื“ื™ื’ื™ื˜ืึทืœืข ื—ืชื™ืžื•ืช (ื“ื™ ื–ืขืœื‘ืข ื—ืชื™ืžื” ื•ื•ืขืจื˜ ื“ื–ืฉืขื ืขืจื™ืจื˜ ืžื™ื˜ ื“ื™ ื–ืขืœื‘ืข ืื™ื ืคึฟื•ื˜ ื“ืึทื˜ืŸ), ืœื•ื™ื˜ ื“ื™ ืจืขืงื•ื•ื™ืจืžืขื ืฅ ืคึฟื•ืŸ ื“ืขื FIPS 186-5 ืกื˜ืึทื ื“ืึทืจื˜.
  • ื“ื™ ืจืขืงื•ื•ื™ื™ืขืจืžืขื ืฅ ืคืืจืŸ ื‘ื•ื™ืขืŸ ืกื‘ื™ื‘ื” ื–ืขื ืขืŸ ืคืืจื’ืจืขืกืขืจื˜ ื’ืขื•ื•ืืจืŸ. ื‘ื•ื™ืขืŸ OpenSSL ืคืืจืœืื ื’ื˜ ืžืขืจ ื ื™ืฉื˜ ืงื™ื™ืŸ ืžื›ืฉื™ืจื™ื ืžื™ื˜ ANSI-C ืฉื˜ื™ืฆืข; ื C-99-ืงืืžืคืื˜ื™ื‘ืœ ืงืืžืคื™ื™ืœืขืจ ืื™ื– ื™ืขืฆื˜ ืคืืจืœืื ื’ื˜.
  • ืคื•ื ืงืฆื™ืขืก ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ื“ืขืจ EVP_PKEY_ASN1_METHOD ืกื˜ืจื•ืงื˜ื•ืจ ื–ืขื ืขืŸ ื’ืขื•ื•ืึธืจืŸ ื“ืขืคึผืจืขืงืึทื˜ืขื“.
  • ืฉื˜ื™ืฆืข ืคืืจ ื“ื™ VxWorks ืคึผืœืึทื˜ืคืึธืจืžืข ืื™ื– ืื•ื™ืคื’ืขื”ืขืจื˜ ื’ืขื•ื•ืึธืจืŸ.

ืคืึทืจืคืขืกื˜ื™ืงื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2025-9230 ืื™ื– ื ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ืŸ ื“ืขื ื“ืขืงืจื™ืคึผื˜ื™ืึธืŸ ืงืึธื“ ืคึฟืึทืจ ืคึผืึทืจืึธืœ-ืขื ืงืจื™ืคึผื˜ืขื“ CMS ืžืขืกืขื“ื–ืฉืขืก (PWRI). ื“ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ ืงืขืŸ ืคื™ืจืŸ ืฆื• ืึทืจื•ื™ืก-ืคื•ืŸ-ื’ืจืขื ืขืฆืŸ ื“ืึทื˜ืŸ ื•ื•ืขืจืŸ ื’ืขืฉืจื™ื‘ืŸ ืึธื“ืขืจ ื’ืขืœืขื–ืŸ, ื•ื•ืึธืก ืงืขืŸ ืคื™ืจืŸ ืฆื• ืึท ืงืจืึทืš ืึธื“ืขืจ ื–ื›ึผืจื•ืŸ ืงืึธืจื•ืคึผืฆื™ืข ืื™ืŸ ืึทืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื•ื•ืึธืก ื ื™ืฆื˜ OpenSSL ืฆื• ืคึผืจืึธืฆืขืกื™ืจืŸ CMS ืžืขืกืขื“ื–ืฉืขืก. ื›ืึธื˜ืฉ ืขืงืกืคึผืœื•ื™ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขื ืฉื•ื•ืื›ืงื™ื™ื˜ ืคึฟืึทืจ ืงืึธื“ ืขืงืกืขืงื•ื˜ื™ืึธืŸ ืื™ื– ืžืขื’ืœืขืš, ื“ื™ ืขืจื ืกื˜ืงื™ื™ื˜ ืคื•ืŸ ื“ืขื ืคึผืจืึธื‘ืœืขื ืื™ื– ืจื™ื“ื•ืกื˜ ื“ื•ืจืš ื“ืขื ืคืึทืงื˜ ืึทื– ืคึผืึทืจืึธืœ-ืขื ืงืจื™ืคึผื˜ืขื“ CMS ืžืขืกืขื“ื–ืฉืขืก ื–ืขื ืขืŸ ื–ืขืœื˜ืŸ ื’ืขื ื™ืฆื˜ ืื™ืŸ ืคึผืจืึทืงืกื™ืก. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• OpenSSL 3.6.0, ื“ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึทืจืจื™ื›ื˜ ืื™ืŸ OpenSSL 3.5.4, 3.4.3, 3.3.5, 3.2.6, ืื•ืŸ 3.0.18. ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืื•ื™ืš ื’ืขื•ื•ืขืŸ ืคืึทืจืจื™ื›ื˜ ืื™ืŸ LibreSSL 4.0.1 ืื•ืŸ 4.1.1, ืึท ื‘ื™ื‘ืœื™ืึธื˜ืขืง ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ื“ื™ OpenBSD ืคึผืจืึธื™ืขืงื˜.
  • CVE-2025-9231 โ€” ื“ื™ ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ืขื SM2 ืืœื’ืืจื™ื˜ื ืื™ื– ืื•ื™ืกื’ืขืฉื˜ืขืœื˜ ืฆื• ื ื–ื™ื™ื˜-ืงืึทื ืึทืœ ืื˜ืืงืข. ืื•ื™ืฃ ืกื™ืกื˜ืขืžืขืŸ ืžื™ื˜ 64-ื‘ื™ื˜ ARM CPUs, ื“ืืก ืขืจืœื•ื™ื‘ื˜ ืคึผืจื™ื•ื•ืึทื˜ืข ืฉืœื™ืกืœ ืึธืคึผื–ื•ืš ื“ื•ืจืš ืึทื ืึทืœื™ื–ื™ืจืŸ ื“ื™ ื˜ื™ื™ืžื™ื ื’ ืคื•ืŸ ื™ื—ื™ื“ ืงืึทืœืงื•ืœืึทืฆื™ืขืก. ื“ื™ ืื˜ืืงืข ืงืขืŸ ืคึผืึธื˜ืขื ืฆื™ืขืœ ื“ื•ืจื›ื’ืขืคื™ืจื˜ ื•ื•ืขืจืŸ ื•ื•ื™ื™ื˜ื ืก. ื“ืขืจ ืจื™ื–ื™ืงืข ืคื•ืŸ โ€‹โ€‹ื“ืขืจ ืื˜ืืงืข ื•ื•ืขืจื˜ ืคืืจืžื™ื ืขืจื˜ ื“ื•ืจืš ื“ืขื ืคืึทืงื˜ ืึทื– OpenSSL ืฉื˜ื™ืฆื˜ ื ื™ืฉื˜ ื’ืœื™ื™ืš ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืกืขืจื˜ื™ืคื™ืงืึทื˜ืŸ ืžื™ื˜ SM2 ืฉืœื™ืกืœืขืŸ ืื™ืŸ TLS.
  • CVE-2025-9232 ืื™ื– ื ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ืŸ ื“ืขืจ ืื™ื™ื ื’ืขื‘ื•ื™ื˜ืขืจ HTTP ืงืœื™ืขื ื˜ ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข ื•ื•ืืก ืขืจืœื•ื™ื‘ื˜ ืื•ื™ืกืขืจ-ื“ื™-ื’ืจืขื ืขืฆืŸ ื“ืื˜ืŸ ืœื™ื™ืขื ืขืŸ ื•ื•ืขืŸ ืžืขืŸ ืคืจืืฆืขืกื™ืจื˜ ื ืกืคืขืฆื™ืขืœ ื’ืขืžืื›ื˜ืข URL ืื™ืŸ HTTP ืงืœื™ืขื ื˜ ืคื•ื ืงืฆื™ืขืก. ื“ื™ ืคืจืื‘ืœืขื ื•ื•ื™ื™ื–ื˜ ื–ื™ืš ื ืืจ ื•ื•ืขืŸ ื“ื™ "no_proxy" ืกื‘ื™ื‘ื” ื•ื•ืขืจื™ืื‘ืœ ืื™ื– ืื™ื™ื ื’ืขืฉื˜ืขืœื˜ ืื•ืŸ ืงืขืŸ ืคื™ืจืŸ ืฆื• ื ืงืจืืš ืคื•ืŸ ื“ืขืจ ืืคืœื™ืงืืฆื™ืข.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’