Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-41677

Опубликовано: 24 апр. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 9.1

Описание

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.

РелизСтатусПримечание
devel

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

needed

jammy

needed

noble

needed

questing

ignored

end of life, was needed
resolute

needed

upstream

released

0.10.78-1

Показывать по

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.

msrc
3 месяца назад

rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length

CVSS3: 9.1
debian
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming langua ...

github
4 месяца назад

rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length

suse-cvrf
15 дней назад

Security update for aws-nitro-enclaves-cli

9.1 Critical

CVSS3