Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-28386

Опубликовано: 07 апр. 2026
Источник: ubuntu
Приоритет: low
CVSS3: 7.5

Описание

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with AVX...

РелизСтатусПримечание
devel

not-affected

3.6+ only
esm-apps-legacy/xenial

not-affected

3.6+ only
esm-apps/bionic

not-affected

3.6+ only
esm-apps/xenial

not-affected

3.6+ only
esm-infra/focal

not-affected

3.6+ only
jammy

not-affected

3.6+ only
noble

not-affected

3.6+ only
questing

not-affected

3.6+ only
upstream

not-affected

3.6+ only

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system openssl
esm-apps-legacy/xenial

not-affected

3.6+ only
esm-apps/bionic

not-affected

3.6+ only
esm-apps/focal

not-affected

uses system openssl
esm-apps/jammy

not-affected

3.6+ only
esm-apps/noble

not-affected

uses system openssl
esm-apps/xenial

not-affected

3.6+ only
esm-infra-legacy/trusty

not-affected

uses system openssl
jammy

not-affected

3.6+ only
noble

not-affected

uses system openssl

Показывать по

РелизСтатусПримечание
devel

not-affected

3.6+ only
esm-infra-legacy/trusty

not-affected

3.6+ only
esm-infra-legacy/xenial

not-affected

3.6+ only
esm-infra/bionic

not-affected

3.6+ only
esm-infra/focal

not-affected

3.6+ only
esm-infra/xenial

not-affected

3.6+ only
fips-preview/jammy

not-affected

3.6+ only
fips-updates/bionic

not-affected

3.6+ only
fips-updates/focal

not-affected

3.6+ only
fips-updates/jammy

not-affected

3.6+ only

Показывать по

РелизСтатусПримечание
devel

DNE

fips-preview/jammy

not-affected

3.6+ only
fips-updates/jammy

not-affected

3.6+ only
fips-updates/noble

not-affected

3.6+ only
jammy

DNE

noble

DNE

questing

DNE

upstream

not-affected

3.6+ only

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

3.6+ only
jammy

DNE

noble

DNE

questing

DNE

upstream

not-affected

3.6+ only

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
4 месяца назад

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with AVX...

CVSS3: 7.5
nvd
4 месяца назад

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with AVX

CVSS3: 7.5
debian
4 месяца назад

Issue summary: Applications using AES-CFB128 encryption or decryption ...

CVSS3: 9.1
github
4 месяца назад

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with ...

7.5 High

CVSS3

Уязвимость CVE-2026-28386