PT-2026-81308 · Openssl+2 · Openssl+2

·

CVE-2026-75803

·

Published

2026-08-22

·

Updated

2026-09-02

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description Decryption using ChaCha20-Poly1305 and AES-OCB ciphers may report success without verifying the authentication tag when an empty ciphertext is processed via the EVP Cipher() function. This occurs because the function skips the AEAD (Authenticated Encryption with Associated Data) tag verification in these specific cases. Consequently, applications relying on the return value of EVP Cipher() to confirm message integrity may accept forged messages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97671
AZL-97884
AZL-97935
CVE-2026-75803
ECHO-F836-71CF-434B
OPENSUSE-SU-2026:11623-1
OPENSUSE-SU-2026:21744-1
RHSA-2026:42825
SUSE-SU-2026:3866-1
SUSE-SU-2026:3876-1
USN-8678-1
USN-8678-3

Affected Products

Linuxmint
Openssl
Ubuntu