Количество 14
Количество 14
CVE-2026-41678
rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of out by in_.len() - 8 - out.len() bytes, causing an out-of-bounds write from a safe public function. This vulnerability is fixed in 0.10.78.
CVE-2026-41678
rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of out by in_.len() - 8 - out.len() bytes, causing an out-of-bounds write from a safe public function. This vulnerability is fixed in 0.10.78.
CVE-2026-41678
rust-openssl: Incorrect bounds assertion in aes key wrap
CVE-2026-41678
rust-openssl provides OpenSSL bindings for the Rust programming langua ...
GHSA-8c75-8mhr-p7r9
rust-openssl has incorrect bounds assertion in aes key wrap
openSUSE-SU-2026:21292-1
Security update for agama
openSUSE-SU-2026:21294-1
Security update for python-cryptography
openSUSE-SU-2026:21285-1
Security update for python-maturin
openSUSE-SU-2026:21274-1
Security update for rust-keylime
SUSE-SU-2026:3040-1
Security update for python-cryptography
SUSE-SU-2026:3026-1
Security update for python-cryptography
SUSE-SU-2026:2832-1
Security update for rustup
SUSE-SU-2026:2831-1
Security update for rustup
SUSE-SU-2026:3022-1
Security update for sccache
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41678 rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of out by in_.len() - 8 - out.len() bytes, causing an out-of-bounds write from a safe public function. This vulnerability is fixed in 0.10.78. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-41678 rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of out by in_.len() - 8 - out.len() bytes, causing an out-of-bounds write from a safe public function. This vulnerability is fixed in 0.10.78. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-41678 rust-openssl: Incorrect bounds assertion in aes key wrap | 0% Низкий | 3 месяца назад | ||
CVE-2026-41678 rust-openssl provides OpenSSL bindings for the Rust programming langua ... | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
GHSA-8c75-8mhr-p7r9 rust-openssl has incorrect bounds assertion in aes key wrap | 0% Низкий | 4 месяца назад | ||
openSUSE-SU-2026:21292-1 Security update for agama | 27 дней назад | |||
openSUSE-SU-2026:21294-1 Security update for python-cryptography | 27 дней назад | |||
openSUSE-SU-2026:21285-1 Security update for python-maturin | 27 дней назад | |||
openSUSE-SU-2026:21274-1 Security update for rust-keylime | 28 дней назад | |||
SUSE-SU-2026:3040-1 Security update for python-cryptography | 22 дня назад | |||
SUSE-SU-2026:3026-1 Security update for python-cryptography | 22 дня назад | |||
SUSE-SU-2026:2832-1 Security update for rustup | 28 дней назад | |||
SUSE-SU-2026:2831-1 Security update for rustup | 28 дней назад | |||
SUSE-SU-2026:3022-1 Security update for sccache | 22 дня назад |
Уязвимостей на страницу