PT-2026-81303 · Openssl+3 · Openssl+3

·

CVE-2026-63072

·

Published

2026-06-18

·

Updated

2026-09-02

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 3.0.22 OpenSSL versions prior to 3.4.7 OpenSSL versions prior to 3.5.8 OpenSSL versions prior to 3.6.4 OpenSSL versions prior to 4.0.2 OpenSSL version 1.1.1
Description An 8-byte out-of-bounds heap write occurs during CMS decryption when the key-unwrap output buffer is sized based on the queried unwrapped key size, but the AES-WRAP-PAD unwrap primitive writes more bytes than reported. An attacker can trigger this by supplying a crafted CMS message and modifying a single OID byte to select the padded variant. This leads to heap corruption and typically results in a Denial of Service. The issue is reachable via the CMS decrypt() function.
Recommendations Upgrade to version 3.0.22. Upgrade to version 3.4.7. Upgrade to version 3.5.8. Upgrade to version 3.6.4. Upgrade to version 4.0.2. As a temporary workaround, restrict the use of the CMS decrypt() function when processing untrusted CMS messages.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97665
AZL-97890
AZL-97947
BDU:2026-13717
CVE-2026-63072
ECHO-AA38-89D5-F024
OPENSUSE-SU-2026:11623-1
OPENSUSE-SU-2026:21744-1
SUSE-SU-2026:3866-1
SUSE-SU-2026:3876-1
SUSE-SU-2026:3877-1
SUSE-SU-2026:3878-1
USN-8678-1
USN-8678-2

Affected Products

Freebsd
Linuxmint
Openssl
Ubuntu