2. CVE-2021-3450 - OpenSSL

Published: 03/25/2021

Recommendation:

X509_V_FLAG_X509_STRICT is never set by edk2.

Until further notice, the following versions of OpenSSL are appropriate to use within the EDK2 CryptoPkg:

  • OpenSSL 1.1.1j, updated in the edk2-stable202105 stable tag
  • OpenSSL 1.1.1n, updated in the edk2-stable202205 stable tag