VYPR

rpm package

almalinux/openssl-perl

pkg:rpm/almalinux/openssl-perl

Vulnerabilities (75)

  • CVE-2026-63076HigAug 25, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced a

  • CVE-2026-63075HigAug 25, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can co

  • CVE-2026-63074MedAug 25, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboun

  • CVE-2026-63073CriAug 25, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a p

  • CVE-2026-63072HigAug 25, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attac

  • CVE-2026-54874HigAug 25, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disprop

  • CVE-2026-18798HigAug 25, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There

  • CVE-2026-14457HigAug 25, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typi

  • CVE-2026-14456HigAug 13, 2026
    affected < 1:3.5.8-1.el10_2.alma.1fixed 1:3.5.8-1.el10_2.alma.1

    Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer that can make many Initial pac

  • CVE-2026-9076HigJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). Impact summary: A heap buffer over-read may trigger a crash w

  • CVE-2026-7383HigJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefine

  • CVE-2026-45447HigJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#

  • CVE-2026-45446MedJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can forge empty messages with arbitra

  • CVE-2026-45445HigJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the same key uses the same effective nonce re

  • CVE-2026-42770LowJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small

  • CVE-2026-42769MedJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Auth

  • CVE-2026-42768LowJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output. Impact summary: The Bleichenbacher-style attack allows an

  • CVE-2026-42767MedJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling

  • CVE-2026-42766MedJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service. The CMS PasswordRecipientInfo.keyDerivationAlgori

  • CVE-2026-42764HigJun 9, 2026
    affected < 1:3.5.5-4.el10_2.alma.1fixed 1:3.5.5-4.el10_2.alma.1

    Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server pro

Page 1 of 4