PT-2026-47831 · Openssl+5 · Openssl+5

·

CVE-2026-34182

·

Published

2026-06-09

·

Updated

2026-09-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers. This allows attackers to achieve key-equivalent functionality for a CMS recipient or bypass integrity validation for a message. In one scenario, an attacker can send a CMS message where the cipher is specified as a non-AEAD (Authenticated Encryption with Associated Data) cipher. If an attacker captures a legitimate AES-GCM AuthEnvelopedData message, they can rewrite the inner OID to AES-256-OFB (an unauthenticated keystream mode) with a chosen IV and ciphertext. If the application provides feedback on the success or failure of the decryption, it can act as an oracle to obtain key-equivalent functionality for the CEK (content-encryption key). Additionally, an attacker can reduce the tag length of an AEAD cipher to a single byte, enabling a brute-force attack to bypass integrity checks in applications relying on the CMS decrypt() function to reject modified content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25237
ALSA-2026:25239
AZL-89802
AZL-89861
AZL-89931
CVE-2026-34182
JLSEC-2026-1135
OESA-2026-2772
OESA-2026-2773
OESA-2026-2781
OESA-2026-2782
OPENSUSE-SU-2026:11023-1
OPENSUSE-SU-2026:21005-1
RHSA-2026:25237
RHSA-2026:25239
SUSE-SU-2026:22100-1
SUSE-SU-2026:22132-1
SUSE-SU-2026:22251-1
SUSE-SU-2026:22315-1
SUSE-SU-2026:2393-1
SUSE-SU-2026:3005-1
SUSE-SU-2026:3094-1
SUSE-SU-2026:3835-1
USN-8414-1
USN-8414-2

Affected Products

Freebsd
Ibm Aix
Linuxmint
Openssl
Rocky Linux
Ubuntu