A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
| Software | From | Fixed in |
|---|---|---|
| openbsd / openbsd | 7.2 | 7.2.x |
| openbsd / libressl | 3.7.0 | 3.7.3 |
| openbsd / libressl | - | 3.6.3 |
| openbsd / openbsd | 7.3 | 7.3.x |