PT-2026-42029 · Openssl+1 · Openssl+1
CVE-2026-45784
·
Published
2026-05-19
·
Updated
2026-09-12
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL (affected versions not specified)
Description
The
CipherCtxRef::cipher update inplace function incorrectly sizes output buffers when utilizing AES key-wrap-with-padding ciphers, specifically EVP aes 128 wrap pad, EVP aes 192 wrap pad, and EVP aes 256 wrap pad. When the input is not a multiple of 8, the system may write up to 7 bytes beyond the end of the caller's buffer or Vec. This leads to heap corruption, which can be controlled by an attacker if the plaintext length is influenced by them.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl
Red Os