PT-2026-81308 · Openssl+2 · Openssl+2
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
Decryption using ChaCha20-Poly1305 and AES-OCB ciphers may report success without verifying the authentication tag when an empty ciphertext is processed via the
EVP Cipher() function. This occurs because the function skips the AEAD (Authenticated Encryption with Associated Data) tag verification in these specific cases. Consequently, applications relying on the return value of EVP Cipher() to confirm message integrity may accept forged messages.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Openssl
Ubuntu