PT-2026-71899 · Rocky Linux · Rocky Linux

·

CVE-2026-56862

·

Published

2026-08-13

·

Updated

2026-09-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description Handshake messages, such as KeyUpdate, are treated as state-advancing regardless of whether a handshake has been completed. This allows a malicious client to continuously send KeyUpdate messages, forcing the server to perform key derivation operations indefinitely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:60304
ALSA-2026:60305
ALSA-2026:60306
ALSA-2026:62406
ALSA-2026:62407
ALSA-2026:62577
ALSA-2026:62578
ALSA-2026:62631
ALSA-2026:63022
ALSA-2026:63119
ALSA-2026:63124
ALSA-2026:63136
ALSA-2026:63332
ALSA-2026:64777
ALSA-2026:64788
ALSA-2026:64818
ALSA-2026:65116
ALSA-2026:65117
ALSA-2026:66016
ALSA-2026:66364
AZL-96662
AZL-96668
AZL-98616
BIT-GOLANG-2026-56862
CVE-2026-56862
GO-2026-6090
OPENSUSE-SU-2026:11516-1
OPENSUSE-SU-2026:11517-1
OPENSUSE-SU-2026:11532-1
OPENSUSE-SU-2026:11536-1
OPENSUSE-SU-2026:11727-1
OPENSUSE-SU-2026:21592-1
OPENSUSE-SU-2026:21593-1
OPENSUSE-SU-2026:21696-1
OPENSUSE-SU-2026:21705-1
OPENSUSE-SU-2026:21761-1
RHSA-2026:64777
RHSA-2026:64786
RHSA-2026:64788
RHSA-2026:64818
RHSA-2026:65116
RHSA-2026:65117
RHSA-2026:65153
RHSA-2026:65335
RHSA-2026:65336
RHSA-2026:65359
RHSA-2026:65534
RHSA-2026:65880
RHSA-2026:65886
RHSA-2026:65895
RHSA-2026:65918
RHSA-2026:66016
RHSA-2026:66327
RHSA-2026:66364
RHSA-2026:66459
SUSE-SU-2026:23300-1
SUSE-SU-2026:23301-1
SUSE-SU-2026:3640-1
SUSE-SU-2026:3641-1
SUSE-SU-2026:3799-1
SUSE-SU-2026:3800-1
SUSE-SU-2026:3815-1
SUSE-SU-2026:3816-1
SUSE-SU-2026:3830-1

Affected Products

Rocky Linux