What is the strategy for introducing bug fixes into the FIPS OpenSSL?
Changes within the cryptographic module need to be evaluated on a case-by-case basis. NIST/CSE permit some degree of modification without requiring a full re-validation, based on a vendor affirmation and/or testing lab review of the extent of changes. The fine print on how much work is required is fairly involved. To date we have no direct experience with any such “letter change” modifications.