OpenSSL
Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response…
Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV…
Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
openssl vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a…
Corregida en Debian 13 y Debian 14.
OpenSSL
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that…
Corregida en Debian 13 y Debian 14.
OpenSSL
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a…
Corregida en Debian 13 y Debian 14.
OpenSSL
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted…
Corregida en Debian 13 y Debian 14.
OpenSSL
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the…
Corregida en Debian 13 y Debian 14.
OpenSSL
Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact…
Sin parche todavía.
OpenSSL
vulnerabilidad de openssl
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.