Количество 20
Количество 20
CVE-2026-41676
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-size bytes). A caller passing a short slice gets a heap/stack overflow from safe code. OpenSSL 3.x providers do check, so this only impacts older OpenSSL. This vulnerability is fixed in 0.10.78.
CVE-2026-41676
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-size bytes). A caller passing a short slice gets a heap/stack overflow from safe code. OpenSSL 3.x providers do check, so this only impacts older OpenSSL. This vulnerability is fixed in 0.10.78.
CVE-2026-41676
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
CVE-2026-41676
rust-openssl provides OpenSSL bindings for the Rust programming langua ...
SUSE-SU-2026:2777-1
Security update for cryptsetup, s390-tools
GHSA-pqf5-4pqq-29f5
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
openSUSE-SU-2026:21464-1
Security update for libkrun
openSUSE-SU-2026:21294-1
Security update for python-cryptography
openSUSE-SU-2026:21285-1
Security update for python-maturin
openSUSE-SU-2026:21274-1
Security update for rust-keylime
openSUSE-SU-2026:21252-1
Security update for clamav
SUSE-SU-2026:3040-1
Security update for python-cryptography
SUSE-SU-2026:3026-1
Security update for python-cryptography
SUSE-SU-2026:2835-1
Security update for clamav
SUSE-SU-2026:2834-1
Security update for clamav
SUSE-SU-2026:2833-1
Security update for clamav
openSUSE-SU-2026:21386-1
Security update for afterburn
SUSE-SU-2026:2832-1
Security update for rustup
SUSE-SU-2026:2831-1
Security update for rustup
SUSE-SU-2026:3022-1
Security update for sccache
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41676 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-size bytes). A caller passing a short slice gets a heap/stack overflow from safe code. OpenSSL 3.x providers do check, so this only impacts older OpenSSL. This vulnerability is fixed in 0.10.78. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41676 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-size bytes). A caller passing a short slice gets a heap/stack overflow from safe code. OpenSSL 3.x providers do check, so this only impacts older OpenSSL. This vulnerability is fixed in 0.10.78. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41676 rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 | 0% Низкий | 3 месяца назад | ||
CVE-2026-41676 rust-openssl provides OpenSSL bindings for the Rust programming langua ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
SUSE-SU-2026:2777-1 Security update for cryptsetup, s390-tools | 0% Низкий | около 1 месяца назад | ||
GHSA-pqf5-4pqq-29f5 rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 | 0% Низкий | 4 месяца назад | ||
openSUSE-SU-2026:21464-1 Security update for libkrun | 9 дней назад | |||
openSUSE-SU-2026:21294-1 Security update for python-cryptography | 27 дней назад | |||
openSUSE-SU-2026:21285-1 Security update for python-maturin | 27 дней назад | |||
openSUSE-SU-2026:21274-1 Security update for rust-keylime | 28 дней назад | |||
openSUSE-SU-2026:21252-1 Security update for clamav | 30 дней назад | |||
SUSE-SU-2026:3040-1 Security update for python-cryptography | 22 дня назад | |||
SUSE-SU-2026:3026-1 Security update for python-cryptography | 22 дня назад | |||
SUSE-SU-2026:2835-1 Security update for clamav | 28 дней назад | |||
SUSE-SU-2026:2834-1 Security update for clamav | 28 дней назад | |||
SUSE-SU-2026:2833-1 Security update for clamav | 28 дней назад | |||
openSUSE-SU-2026:21386-1 Security update for afterburn | 17 дней назад | |||
SUSE-SU-2026:2832-1 Security update for rustup | 28 дней назад | |||
SUSE-SU-2026:2831-1 Security update for rustup | 28 дней назад | |||
SUSE-SU-2026:3022-1 Security update for sccache | 22 дня назад |
Уязвимостей на страницу