Количество 22
Количество 22
GHSA-7x88-9hgc-69gf
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
CVE-2026-28389
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in D...
CVE-2026-28389
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
CVE-2026-28389
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
CVE-2026-28389
Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo
CVE-2026-28389
Issue summary: During processing of a crafted CMS EnvelopedData messag ...
BDU:2026-10555
Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260713-73-0036
Уязвимость python-relenv
SUSE-SU-2026:1290-1
Security update for openssl-1_1
SUSE-SU-2026:1255-1
Security update for openssl-1_1
SUSE-SU-2026:1577-1
Security update for openssl-1_1
SUSE-SU-2026:1386-1
Security update for openssl-1_1
SUSE-SU-2026:1291-1
Security update for openssl-1_0_0
SUSE-SU-2026:1257-1
Security update for openssl-1_1
SUSE-SU-2026:1256-1
Security update for openssl-1_0_0
SUSE-SU-2026:1215-1
Security update for openssl-3
SUSE-SU-2026:1214-1
Security update for openssl-3
SUSE-SU-2026:1213-1
Security update for openssl-3
SUSE-SU-2026:1375-1
Security update for openssl-3
openSUSE-SU-2026:20525-1
Security update for openssl-3
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-7x88-9hgc-69gf Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-28389 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in D... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-28389 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. | CVSS3: 5.9 | 1% Низкий | 4 месяца назад | |
CVE-2026-28389 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-28389 Issue summary: During processing of a crafted CMS EnvelopedData messag ... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
BDU:2026-10555 Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
ROS-20260713-73-0036 Уязвимость python-relenv | CVSS3: 7.5 | 1% Низкий | 18 дней назад | |
SUSE-SU-2026:1290-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1255-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1577-1 Security update for openssl-1_1 | 3 месяца назад | |||
SUSE-SU-2026:1386-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1291-1 Security update for openssl-1_0_0 | 4 месяца назад | |||
SUSE-SU-2026:1257-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1256-1 Security update for openssl-1_0_0 | 4 месяца назад | |||
SUSE-SU-2026:1215-1 Security update for openssl-3 | 4 месяца назад | |||
SUSE-SU-2026:1214-1 Security update for openssl-3 | 4 месяца назад | |||
SUSE-SU-2026:1213-1 Security update for openssl-3 | 4 месяца назад | |||
SUSE-SU-2026:1375-1 Security update for openssl-3 | 4 месяца назад | |||
openSUSE-SU-2026:20525-1 Security update for openssl-3 | 4 месяца назад |
Уязвимостей на страницу