Количество 33
Количество 33
GHSA-f684-cpcq-j565
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected...
CVE-2026-45447
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Ap...
CVE-2026-45447
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Ap...
CVE-2026-45447
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. A
CVE-2026-45447
Heap Use-After-Free in the PKCS7_verify() Function
CVE-2026-45447
Issue summary: A specially crafted PKCS#7 or S/MIME signed message cou ...
SUSE-SU-2026:2621-1
Security update for openssl-1_1-livepatches
SUSE-SU-2026:2412-1
Security update for openssl-1_1-livepatches
SUSE-SU-2026:2410-1
Security update for openssl-1_1-livepatches
SUSE-SU-2026:2409-1
Security update for openssl-1_1-livepatches
RLSA-2026:36215
Important: compat-openssl10 security update
ELSA-2026-36215
ELSA-2026-36215: compat-openssl10 security update (IMPORTANT)
RLSA-2026:26275
Important: openssl security update
ELSA-2026-50323
ELSA-2026-50323: openssl security update (IMPORTANT)
ELSA-2026-26275
ELSA-2026-26275: openssl security update (IMPORTANT)
SUSE-SU-2026:2662-1
Security update for openssl-3-livepatches
SUSE-SU-2026:2411-1
Security update for openssl-3-livepatches
SUSE-SU-2026:2614-1
Security update for openssl-1_1
SUSE-SU-2026:2405-1
Security update for openssl-1_1
SUSE-SU-2026:2404-1
Security update for openssl-1_1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-f684-cpcq-j565 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected... | CVSS3: 9.8 | 3% Низкий | около 2 месяцев назад | |
CVE-2026-45447 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Ap... | CVSS3: 8.8 | 3% Низкий | около 2 месяцев назад | |
CVE-2026-45447 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Ap... | CVSS3: 8.1 | 3% Низкий | около 2 месяцев назад | |
CVE-2026-45447 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. A | CVSS3: 8.8 | 3% Низкий | около 2 месяцев назад | |
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function | CVSS3: 8.8 | 3% Низкий | около 1 месяца назад | |
CVE-2026-45447 Issue summary: A specially crafted PKCS#7 or S/MIME signed message cou ... | CVSS3: 8.8 | 3% Низкий | около 2 месяцев назад | |
SUSE-SU-2026:2621-1 Security update for openssl-1_1-livepatches | 3% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2412-1 Security update for openssl-1_1-livepatches | 3% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2410-1 Security update for openssl-1_1-livepatches | 3% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2409-1 Security update for openssl-1_1-livepatches | 3% Низкий | около 1 месяца назад | ||
RLSA-2026:36215 Important: compat-openssl10 security update | 3% Низкий | 18 дней назад | ||
ELSA-2026-36215 ELSA-2026-36215: compat-openssl10 security update (IMPORTANT) | 24 дня назад | |||
RLSA-2026:26275 Important: openssl security update | около 1 месяца назад | |||
ELSA-2026-50323 ELSA-2026-50323: openssl security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-26275 ELSA-2026-26275: openssl security update (IMPORTANT) | около 2 месяцев назад | |||
SUSE-SU-2026:2662-1 Security update for openssl-3-livepatches | около 1 месяца назад | |||
SUSE-SU-2026:2411-1 Security update for openssl-3-livepatches | около 1 месяца назад | |||
SUSE-SU-2026:2614-1 Security update for openssl-1_1 | около 1 месяца назад | |||
SUSE-SU-2026:2405-1 Security update for openssl-1_1 | около 2 месяцев назад | |||
SUSE-SU-2026:2404-1 Security update for openssl-1_1 | около 2 месяцев назад |
Уязвимостей на страницу