High scoring openssl vulnerability CVE-2025-15467 - install + reboot

Discuss your pilot or production implementation with other Zimbra admins or our engineers.
zmcontrol
Advanced member
Advanced member
Posts: 70
Joined: Fri Jul 24, 2020 12:43 am

Re: High scoring openssl vulnerability CVE-2025-15467 - install + reboot

Post by zmcontrol »

ghen wrote: Wed Feb 04, 2026 7:29 am There are no Zimbra customizations, Zimbra isn't patching OpenSSL (and never has). Just change the version number and build.
ghen,

You are correct!
The build was successful after updating only OPENSSL_VERSION to 3.5.5 in versions.def, and prepending zimbra-openssl/../changelog to reflect 3.5.5 and the proper build date/time. So far no noticeable issues while testing.
Much thanks for your clarification and references.
Post Reply