Количество 18
Количество 18
CVE-2026-45784
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.
CVE-2026-45784
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.
CVE-2026-45784
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.
CVE-2026-45784
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
CVE-2026-45784
rust-openssl provides OpenSSL bindings for the Rust programming langua ...
GHSA-phqj-4mhp-q6mq
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
openSUSE-SU-2026:21406-1
Security update for aws-nitro-enclaves-cli
openSUSE-SU-2026:21292-1
Security update for agama
SUSE-SU-2026:3152-1
Security update for aws-nitro-enclaves-cli
openSUSE-SU-2026:21294-1
Security update for python-cryptography
openSUSE-SU-2026:21285-1
Security update for python-maturin
openSUSE-SU-2026:21274-1
Security update for rust-keylime
SUSE-SU-2026:3040-1
Security update for python-cryptography
SUSE-SU-2026:3026-1
Security update for python-cryptography
openSUSE-SU-2026:21386-1
Security update for afterburn
SUSE-SU-2026:2832-1
Security update for rustup
SUSE-SU-2026:2831-1
Security update for rustup
SUSE-SU-2026:3022-1
Security update for sccache
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-45784 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80. | CVSS3: 7.1 | 0% Низкий | 19 дней назад | |
CVE-2026-45784 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80. | CVSS3: 5.1 | 0% Низкий | 19 дней назад | |
CVE-2026-45784 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80. | CVSS3: 7.1 | 0% Низкий | 19 дней назад | |
CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | 0% Низкий | 18 дней назад | ||
CVE-2026-45784 rust-openssl provides OpenSSL bindings for the Rust programming langua ... | CVSS3: 7.1 | 0% Низкий | 19 дней назад | |
GHSA-phqj-4mhp-q6mq rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | 0% Низкий | 3 месяца назад | ||
openSUSE-SU-2026:21406-1 Security update for aws-nitro-enclaves-cli | 15 дней назад | |||
openSUSE-SU-2026:21292-1 Security update for agama | 26 дней назад | |||
SUSE-SU-2026:3152-1 Security update for aws-nitro-enclaves-cli | 15 дней назад | |||
openSUSE-SU-2026:21294-1 Security update for python-cryptography | 26 дней назад | |||
openSUSE-SU-2026:21285-1 Security update for python-maturin | 26 дней назад | |||
openSUSE-SU-2026:21274-1 Security update for rust-keylime | 27 дней назад | |||
SUSE-SU-2026:3040-1 Security update for python-cryptography | 21 день назад | |||
SUSE-SU-2026:3026-1 Security update for python-cryptography | 21 день назад | |||
openSUSE-SU-2026:21386-1 Security update for afterburn | 16 дней назад | |||
SUSE-SU-2026:2832-1 Security update for rustup | 27 дней назад | |||
SUSE-SU-2026:2831-1 Security update for rustup | 27 дней назад | |||
SUSE-SU-2026:3022-1 Security update for sccache | 21 день назад |
Уязвимостей на страницу