Количество 29
Количество 29
BDU:2026-13717
Уязвимость функции CMS_decrypt() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2026-63072
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decrypt...
CVE-2026-63072
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decrypt...
CVE-2026-63072
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decrypt
CVE-2026-63072
Heap Buffer Overflow in CMS Key Unwrapping
CVE-2026-63072
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buff ...
SUSE-SU-2026:4042-1
Security update for openssl-1_1-livepatches
SUSE-SU-2026:4037-1
Security update for openssl-1_1-livepatches
SUSE-SU-2026:4036-1
Security update for openssl-1_1-livepatches
SUSE-SU-2026:4034-1
Security update for openssl-1_1-livepatches
GHSA-wp5f-6q39-q2f4
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decr...
SUSE-SU-2026:4043-1
Security update for openssl-1_1
SUSE-SU-2026:4041-1
Security update for openssl-1_1
SUSE-SU-2026:4033-1
Security update for openssl-1_1
SUSE-SU-2026:3878-1
Security update for openssl-1_1
SUSE-SU-2026:3877-1
Security update for openssl-1_1
SUSE-SU-2026:4040-1
Security update for openssl-3-livepatches
SUSE-SU-2026:4038-1
Security update for openssl-3-livepatches
SUSE-SU-2026:4032-1
Security update for openssl-3
SUSE-SU-2026:3876-1
Security update for openssl-3
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-13717 Уязвимость функции CMS_decrypt() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-63072 Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decrypt... | CVSS3: 7.5 | 1% Низкий | 25 дней назад | |
CVE-2026-63072 Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decrypt... | CVSS3: 7.5 | 1% Низкий | 26 дней назад | |
CVE-2026-63072 Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decrypt | CVSS3: 7.5 | 1% Низкий | 25 дней назад | |
CVE-2026-63072 Heap Buffer Overflow in CMS Key Unwrapping | 1% Низкий | 13 дней назад | ||
CVE-2026-63072 Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buff ... | CVSS3: 7.5 | 1% Низкий | 25 дней назад | |
SUSE-SU-2026:4042-1 Security update for openssl-1_1-livepatches | 1% Низкий | 12 дней назад | ||
SUSE-SU-2026:4037-1 Security update for openssl-1_1-livepatches | 1% Низкий | 12 дней назад | ||
SUSE-SU-2026:4036-1 Security update for openssl-1_1-livepatches | 1% Низкий | 12 дней назад | ||
SUSE-SU-2026:4034-1 Security update for openssl-1_1-livepatches | 1% Низкий | 12 дней назад | ||
GHSA-wp5f-6q39-q2f4 Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decr... | CVSS3: 7.5 | 1% Низкий | 25 дней назад | |
SUSE-SU-2026:4043-1 Security update for openssl-1_1 | 12 дней назад | |||
SUSE-SU-2026:4041-1 Security update for openssl-1_1 | 12 дней назад | |||
SUSE-SU-2026:4033-1 Security update for openssl-1_1 | 12 дней назад | |||
SUSE-SU-2026:3878-1 Security update for openssl-1_1 | 19 дней назад | |||
SUSE-SU-2026:3877-1 Security update for openssl-1_1 | 19 дней назад | |||
SUSE-SU-2026:4040-1 Security update for openssl-3-livepatches | 12 дней назад | |||
SUSE-SU-2026:4038-1 Security update for openssl-3-livepatches | 12 дней назад | |||
SUSE-SU-2026:4032-1 Security update for openssl-3 | 12 дней назад | |||
SUSE-SU-2026:3876-1 Security update for openssl-3 | 19 дней назад |
Уязвимостей на страницу