OpenSSL: Mehrere Schwachstellen
Multiple security vulnerabilities were identified in OpenSSL affecting various versions used in distributions such as Ubuntu, Amazon Linux 2, and Debian. These issues include incorrect key exchange negotiation in TLS 1. 3, improper memory handling leading to potential crashes or code execution, and information disclosure via RSA KEM RSASVE encapsulation failures. The vulnerabilities could allow remote attackers to cause denial of service, possibly execute arbitrary code, or obtain sensitive information. Official patches have been released by Ubuntu for affected versions, and users are advised to update their OpenSSL packages and reboot systems to apply fixes.
AI Analysis
Technical Summary
The Bundesamt für Sicherheit in der Informationstechnik reported multiple vulnerabilities in OpenSSL, including CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, and CVE-2026-31790, among others. These vulnerabilities involve incorrect negotiation of preferred key exchange groups in TLS 1.3 servers, improper memory handling in DANE clients and delta CRL processing, and crafted CMS EnvelopedData message processing errors. Some issues may lead to denial of service or remote code execution, while one vulnerability may allow sensitive information disclosure. Ubuntu has released security updates across multiple releases (14.04 LTS through 25.10) addressing these flaws. The fixes require standard system updates and rebooting to complete installation.
Potential Impact
Remote attackers could exploit these vulnerabilities to cause OpenSSL to crash, resulting in denial of service, or potentially execute arbitrary code. One vulnerability could allow attackers to obtain sensitive information. The incorrect negotiation of key exchange groups in TLS 1.3 could lead to the use of less preferred cryptographic parameters, potentially weakening security. These impacts affect systems running vulnerable OpenSSL versions on various Linux distributions.
Mitigation Recommendations
Official security updates have been released by Ubuntu for all affected versions, including 14.04 LTS through 25.10. Users should apply these updates promptly and reboot their systems to ensure all fixes are active. Ubuntu Pro provides extended security coverage and is recommended for long-term support. No additional vendor advisories indicate that no action is required; therefore, applying the official patches is the primary mitigation.
OpenSSL: Mehrere Schwachstellen
Description
Multiple security vulnerabilities were identified in OpenSSL affecting various versions used in distributions such as Ubuntu, Amazon Linux 2, and Debian. These issues include incorrect key exchange negotiation in TLS 1. 3, improper memory handling leading to potential crashes or code execution, and information disclosure via RSA KEM RSASVE encapsulation failures. The vulnerabilities could allow remote attackers to cause denial of service, possibly execute arbitrary code, or obtain sensitive information. Official patches have been released by Ubuntu for affected versions, and users are advised to update their OpenSSL packages and reboot systems to apply fixes.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Bundesamt für Sicherheit in der Informationstechnik reported multiple vulnerabilities in OpenSSL, including CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, and CVE-2026-31790, among others. These vulnerabilities involve incorrect negotiation of preferred key exchange groups in TLS 1.3 servers, improper memory handling in DANE clients and delta CRL processing, and crafted CMS EnvelopedData message processing errors. Some issues may lead to denial of service or remote code execution, while one vulnerability may allow sensitive information disclosure. Ubuntu has released security updates across multiple releases (14.04 LTS through 25.10) addressing these flaws. The fixes require standard system updates and rebooting to complete installation.
Potential Impact
Remote attackers could exploit these vulnerabilities to cause OpenSSL to crash, resulting in denial of service, or potentially execute arbitrary code. One vulnerability could allow attackers to obtain sensitive information. The incorrect negotiation of key exchange groups in TLS 1.3 could lead to the use of less preferred cryptographic parameters, potentially weakening security. These impacts affect systems running vulnerable OpenSSL versions on various Linux distributions.
Mitigation Recommendations
Official security updates have been released by Ubuntu for all affected versions, including 14.04 LTS through 25.10. Users should apply these updates promptly and reboot their systems to ensure all fixes are active. Ubuntu Pro provides extended security coverage and is recommended for long-term support. No additional vendor advisories indicate that no action is required; therefore, applying the official patches is the primary mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_base
- Csaf Version
- 2.0
- Publisher
- Bundesamt für Sicherheit in der Informationstechnik
- Advisory Id
- WID-SEC-W-2026-0995
- Cve Count
- 7
- Additional Cves
- ["CVE-2026-28387","CVE-2026-28388","CVE-2026-28389","CVE-2026-28390","CVE-2026-31789","CVE-2026-31790"]
- Cvss Version
- null
Threat ID: 6a18abafe29bf47b5028af22
Added to database: 5/28/2026, 8:55:11 PM
Last enriched: 5/28/2026, 9:22:01 PM
Last updated: 5/28/2026, 10:16:21 PM
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.