OpenSSL Advisory: April 7th, 2026 (BoringSSL Not Affected)

OpenSSL have published a security advisory. Here's how it affects BoringSSL:

CVESummarySeverity in OpenSSLImpact to BoringSSL
CVE-2026-31790Incorrect Failure Handling in RSA KEM RSASVE EncapsulationModerateNot affected, issue was introduced after fork
CVE-2026-28386Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 SupportLowNot affected, issue was introduced after fork
CVE-2026-28387Potential Use-after-free in DANE Client CodeLowNot affected, issue was introduced after fork
CVE-2026-28388NULL Pointer Dereference When Processing a Delta CRLLowNot affected, impacted code was removed from BoringSSL in November 2023
CVE-2026-28389Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfoLowNot affected, impacted code was removed from BoringSSL in the initial fork
CVE-2026-28390Possible NULL Dereference When Processing CMS KeyTransportRecipientInfoLowNot affected, impacted code was removed from BoringSSL in the initial fork
CVE-2026-31789Heap Buffer Overflow in Hexadecimal ConversionLowNot affected, issue was introduced after fork