Forthcoming OpenSSL Releases – Critical Issue in OpenSSL 3

  • This seems to affect only OpenSSL 3.x.x

    Most distros have never bothered to upgrade to major version 3 - possibly because it broke ABI backwards compatibility - so despite the critical severity the impact might not be as widespread as it could have been?

  • RCE and unprivileged access to memory? (to dump keys and the like)

    seems fun

  • No cute name / logo for this one?