PT-2026-81303 · Openssl+3 · Openssl+3
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 3.0.22
OpenSSL versions prior to 3.4.7
OpenSSL versions prior to 3.5.8
OpenSSL versions prior to 3.6.4
OpenSSL versions prior to 4.0.2
OpenSSL version 1.1.1
Description
An 8-byte out-of-bounds heap write occurs during CMS decryption when the key-unwrap output buffer is sized based on the queried unwrapped key size, but the AES-WRAP-PAD unwrap primitive writes more bytes than reported. An attacker can trigger this by supplying a crafted CMS message and modifying a single OID byte to select the padded variant. This leads to heap corruption and typically results in a Denial of Service. The issue is reachable via the
CMS decrypt() function.Recommendations
Upgrade to version 3.0.22.
Upgrade to version 3.4.7.
Upgrade to version 3.5.8.
Upgrade to version 3.6.4.
Upgrade to version 4.0.2.
As a temporary workaround, restrict the use of the
CMS decrypt() function when processing untrusted CMS messages.Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd
Linuxmint
Openssl
Ubuntu