The OpenSSL project maintainers have released patches to address a high-severity bug in the cryptographic library that could potentially lead to remote code execution under certain scenarios.
See also: Apple: New Lockdown Mode will offer protection against spyware

The issue, now assigned the identifier CVE-2022-2274, has been described as a heap memory corruption issue with RSA private key functionality introduced in OpenSSL version 3.0.4 released on June 21, 2022.
See also: SHI International: Hit by malware attack
OpenSSL, first released in 1998, is a general-purpose cryptography library that provides an open-source implementation of the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, allowing users to generate private keys, create certificate signing requests (CSRs), and install SSL/TLS certificates.
"SSL/TLS servers or other servers using 2048-bit RSA private keys running on machines that support AVX512IFMA instructions on the X86_64 architecture are affected by this issue," the announcement notes.
Calling it a “serious bug in the RSA implementation,” the maintainers said the flaw could lead to memory corruption during computation that could be weaponized by an attacker to enable remote code execution on the machine performing the computation.

See also: Marriott: New data breach for the hotel chain
Xi Ruoyao, a Ph.D. student at Xidian University, reported the flaw in OpenSSL on June 22, 2022. Users of the library are advised to upgrade to OpenSSL version 3.0.5 to mitigate any potential threats.
Information source: thehackernews.com
