Security update for openssl-3
This security update for OpenSSL 3 addresses multiple vulnerabilities including remote denial-of-service via expensive Diffie-Hellman key agreement computations, heap buffer overflows, out-of-bounds reads, null pointer dereferences, acceptance of forged CMS messages, and cryptographic processing errors in AES modes. These issues affect the OpenSSL 3 library and could lead to crashes, memory corruption, or cryptographic failures.
AI Analysis
Technical Summary
The update for OpenSSL 3 fixes several vulnerabilities: CVE-2024-41996 allows remote attackers to trigger expensive server-side Diffie-Hellman computations by manipulating public key order; CVE-2026-7383 is a possible heap buffer overflow in ASN.1 multibyte string conversion; CVE-2026-9076 is an out-of-bounds read in CMS password-based decryption; CVE-2026-28390 involves a null pointer dereference during processing of crafted CMS EnvelopedData messages; CVE-2026-34180 is a heap buffer over-read in ASN.1 content parsing; CVE-2026-34182 allows acceptance of forged CMS AuthEnvelopedData messages; CVE-2026-42766 is a possible null dereference in password-based CMS decryption; CVE-2026-42770 involves FFC-DH peer validation using attacker-supplied parameters; CVE-2026-45445 and CVE-2026-45446 relate to incorrect IV and tag processing in AES-OCB and AES-GCM-SIV/AES-SIV modes; CVE-2026-45447 is a heap use-after-free in PKCS7_verify(). These vulnerabilities collectively impact cryptographic operations and message processing in OpenSSL 3.
Potential Impact
The vulnerabilities can lead to denial-of-service conditions via resource exhaustion, memory corruption including heap buffer overflows and use-after-free, out-of-bounds memory reads, null pointer dereferences causing crashes, acceptance of forged cryptographic messages, and incorrect cryptographic processing potentially undermining message confidentiality and integrity. These issues affect the security and stability of applications relying on OpenSSL 3 for cryptographic functions.
Mitigation Recommendations
A security update for OpenSSL 3 has been released addressing these vulnerabilities. Users should apply the official OpenSSL 3 update provided by their vendor or distribution to remediate these issues. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor advisory for current remediation guidance and apply updates accordingly.
Security update for openssl-3
Description
This security update for OpenSSL 3 addresses multiple vulnerabilities including remote denial-of-service via expensive Diffie-Hellman key agreement computations, heap buffer overflows, out-of-bounds reads, null pointer dereferences, acceptance of forged CMS messages, and cryptographic processing errors in AES modes. These issues affect the OpenSSL 3 library and could lead to crashes, memory corruption, or cryptographic failures.
Affected software
pkg:rpm/suse/libopenssl3Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The update for OpenSSL 3 fixes several vulnerabilities: CVE-2024-41996 allows remote attackers to trigger expensive server-side Diffie-Hellman computations by manipulating public key order; CVE-2026-7383 is a possible heap buffer overflow in ASN.1 multibyte string conversion; CVE-2026-9076 is an out-of-bounds read in CMS password-based decryption; CVE-2026-28390 involves a null pointer dereference during processing of crafted CMS EnvelopedData messages; CVE-2026-34180 is a heap buffer over-read in ASN.1 content parsing; CVE-2026-34182 allows acceptance of forged CMS AuthEnvelopedData messages; CVE-2026-42766 is a possible null dereference in password-based CMS decryption; CVE-2026-42770 involves FFC-DH peer validation using attacker-supplied parameters; CVE-2026-45445 and CVE-2026-45446 relate to incorrect IV and tag processing in AES-OCB and AES-GCM-SIV/AES-SIV modes; CVE-2026-45447 is a heap use-after-free in PKCS7_verify(). These vulnerabilities collectively impact cryptographic operations and message processing in OpenSSL 3.
Potential Impact
The vulnerabilities can lead to denial-of-service conditions via resource exhaustion, memory corruption including heap buffer overflows and use-after-free, out-of-bounds memory reads, null pointer dereferences causing crashes, acceptance of forged cryptographic messages, and incorrect cryptographic processing potentially undermining message confidentiality and integrity. These issues affect the security and stability of applications relying on OpenSSL 3 for cryptographic functions.
Mitigation Recommendations
A security update for OpenSSL 3 has been released addressing these vulnerabilities. Users should apply the official OpenSSL 3 update provided by their vendor or distribution to remediate these issues. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor advisory for current remediation guidance and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- SUSE-SU-2026:22132-1
- Cve Count
- 11
- Additional Cves
- ["CVE-2026-28390","CVE-2026-34180","CVE-2026-34182","CVE-2026-42766","CVE-2026-42770","CVE-2026-45445","CVE-2026-45446","CVE-2026-45447","CVE-2026-7383","CVE-2026-9076"]
- State
- PUBLISHED
Threat ID: 6abc27d5680226ef6846f988
Added to database: 09/29/2026, 21:04:21 UTC
Last enriched: 09/29/2026, 21:26:42 UTC
Last updated: 09/30/2026, 03:28:22 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.