Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41677

Опубликовано: 24 апр. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rust-openssl_project:rust-openssl:*:*:*:*:*:rust:*:*
Версия от 0.9.0 (включая) до 0.10.78 (исключая)

EPSS

Процентиль: 21%
0.00294
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.

msrc
3 месяца назад

rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length

CVSS3: 9.1
debian
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming langua ...

github
4 месяца назад

rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length

suse-cvrf
15 дней назад

Security update for aws-nitro-enclaves-cli

EPSS

Процентиль: 21%
0.00294
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-125