Количество 22
Количество 22
GHSA-vgxx-5xj5-q97x
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacke...
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i...
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i...
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i
CVE-2026-31790
Incorrect Failure Handling in RSA KEM RSASVE Encapsulation
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establis ...
ROS-20260713-73-0030
Уязвимость python-relenv
RLSA-2026:19218
Moderate: openssl security update
RLSA-2026:19066
Moderate: openssl security update
ELSA-2026-500005
ELSA-2026-500005: openssl security update (MODERATE)
ELSA-2026-19218
ELSA-2026-19218: openssl security update (MODERATE)
ELSA-2026-19066
ELSA-2026-19066: openssl security update (MODERATE)
RLSA-2026:39297
Moderate: edk2 security, bug fix, and enhancement update
ELSA-2026-39297
ELSA-2026-39297: edk2 security, bug fix, and enhancement update (MODERATE)
SUSE-SU-2026:1291-1
Security update for openssl-1_0_0
SUSE-SU-2026:1257-1
Security update for openssl-1_1
SUSE-SU-2026:1256-1
Security update for openssl-1_0_0
SUSE-SU-2026:1215-1
Security update for openssl-3
SUSE-SU-2026:1214-1
Security update for openssl-3
SUSE-SU-2026:1213-1
Security update for openssl-3
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-vgxx-5xj5-q97x Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacke... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i... | CVSS3: 5.9 | 1% Низкий | 4 месяца назад | |
CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-31790 Incorrect Failure Handling in RSA KEM RSASVE Encapsulation | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establis ... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
ROS-20260713-73-0030 Уязвимость python-relenv | CVSS3: 7.5 | 1% Низкий | 18 дней назад | |
RLSA-2026:19218 Moderate: openssl security update | 1% Низкий | 2 месяца назад | ||
RLSA-2026:19066 Moderate: openssl security update | 1% Низкий | 2 месяца назад | ||
ELSA-2026-500005 ELSA-2026-500005: openssl security update (MODERATE) | 16 дней назад | |||
ELSA-2026-19218 ELSA-2026-19218: openssl security update (MODERATE) | около 2 месяцев назад | |||
ELSA-2026-19066 ELSA-2026-19066: openssl security update (MODERATE) | 23 дня назад | |||
RLSA-2026:39297 Moderate: edk2 security, bug fix, and enhancement update | 16 дней назад | |||
ELSA-2026-39297 ELSA-2026-39297: edk2 security, bug fix, and enhancement update (MODERATE) | 15 дней назад | |||
SUSE-SU-2026:1291-1 Security update for openssl-1_0_0 | 4 месяца назад | |||
SUSE-SU-2026:1257-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1256-1 Security update for openssl-1_0_0 | 4 месяца назад | |||
SUSE-SU-2026:1215-1 Security update for openssl-3 | 4 месяца назад | |||
SUSE-SU-2026:1214-1 Security update for openssl-3 | 4 месяца назад | |||
SUSE-SU-2026:1213-1 Security update for openssl-3 | 4 месяца назад |
Уязвимостей на страницу