Vulnerabilidades de OpenSSL

Vulnerabilidades de la biblioteca criptográfica que sostiene TLS en casi todo el sistema. Ahora mismo seguimos 14 avisos, 13 con versión corregida publicada.

CVE-2026-35189 Media 5.3 2026-09-29

OpenSSL

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-54872 Baja 3.7 2026-09-29

OpenSSL

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-75805 Media 5.3 2026-09-29

OpenSSL

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-75806 Media 5.3 2026-09-29

OpenSSL

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-77696 Baja 3.7 2026-09-29

OpenSSL

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-84782 Alta 8.2 2026-09-29

OpenSSL

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14456 Sin clasificar 2026-08-25

OpenSSL

openssl vulnerabilities

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-54874 Alta 7.5 2026-08-25

OpenSSL

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a…

Corregida en Debian 13 y Debian 14.

CVE-2026-63072 Alta 7.5 2026-08-25

OpenSSL

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that…

Corregida en Debian 13 y Debian 14.

CVE-2026-63074 Media 5.9 2026-08-25

OpenSSL

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a…

Corregida en Debian 13 y Debian 14.

CVE-2026-63076 Alta 7.5 2026-08-25

OpenSSL

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted…

Corregida en Debian 13 y Debian 14.

CVE-2026-75803 Crítica 9.1 2026-08-25

OpenSSL

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the…

Corregida en Debian 13 y Debian 14.

CVE-2026-54876 Alta 7.5 2026-08-05

OpenSSL

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact…

Sin parche todavía.

USN-8625-1 Sin clasificar 2026-07-30

OpenSSL

vulnerabilidad de openssl

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

Datos de OSV.dev, publicados bajo licencia CC BY 4.0. Se recopilan a diario y se filtran al software que seguimos; así se elabora la lista.