Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-41677

Опубликовано: 26 апр. 2026
Источник: msrc
EPSS Низкий

Описание

rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length

EPSS

Процентиль: 22%
0.00294
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.

CVSS3: 9.1
nvd
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.

CVSS3: 9.1
debian
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming langua ...

github
4 месяца назад

rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length

suse-cvrf
15 дней назад

Security update for aws-nitro-enclaves-cli

EPSS

Процентиль: 22%
0.00294
Низкий