A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "3.6.3"
},
{
"introduced": "3.7.0"
},
{
"fixed": "3.7.3"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-35784.json"
[
{
"id": "CVE-2023-35784-6b7f9c19",
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/libressl/openbsd/commit/e42d8f4b21a8a498e2eabbffe4c7b7d4ef7cec54",
"deprecated": false,
"digest": {
"function_hash": "275837915516327575572512449369328465332",
"length": 1139.0
},
"target": {
"function": "ssl3_free",
"file": "src/lib/libssl/s3_lib.c"
}
},
{
"id": "CVE-2023-35784-81ca270c",
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/libressl/openbsd/commit/e42d8f4b21a8a498e2eabbffe4c7b7d4ef7cec54",
"deprecated": false,
"digest": {
"line_hashes": [
"318029086928463328978880662858799719559",
"38581269024580834936979536530738007553",
"289431370978073966754050857004753806111",
"237554259802663005882124020248922010992",
"55220800006065477010725795313990725964"
],
"threshold": 0.9
},
"target": {
"file": "src/lib/libssl/s3_lib.c"
}
}
]
"2026-04-12T05:13:22Z"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3"
}
]
}
]