Skip to main content
EPSS 1.1%top 36%

Security update for openssl-3

0
High
Published: 06/11/2026 (06/11/2026, 12:42:44 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This security update for OpenSSL 3 addresses multiple vulnerabilities including remote denial-of-service via expensive Diffie-Hellman key agreement computations, heap buffer overflows, out-of-bounds reads, null pointer dereferences, acceptance of forged CMS messages, and cryptographic processing errors in AES modes. These issues affect the OpenSSL 3 library and could lead to crashes, memory corruption, or cryptographic failures.

Affected software

suse/libopenssl3
pkg:rpm/suse/libopenssl3
Affected versions
<3.1.4-slfo.1.1_10.1.aarch64

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 21:26:42 UTC

Technical Analysis

The update for OpenSSL 3 fixes several vulnerabilities: CVE-2024-41996 allows remote attackers to trigger expensive server-side Diffie-Hellman computations by manipulating public key order; CVE-2026-7383 is a possible heap buffer overflow in ASN.1 multibyte string conversion; CVE-2026-9076 is an out-of-bounds read in CMS password-based decryption; CVE-2026-28390 involves a null pointer dereference during processing of crafted CMS EnvelopedData messages; CVE-2026-34180 is a heap buffer over-read in ASN.1 content parsing; CVE-2026-34182 allows acceptance of forged CMS AuthEnvelopedData messages; CVE-2026-42766 is a possible null dereference in password-based CMS decryption; CVE-2026-42770 involves FFC-DH peer validation using attacker-supplied parameters; CVE-2026-45445 and CVE-2026-45446 relate to incorrect IV and tag processing in AES-OCB and AES-GCM-SIV/AES-SIV modes; CVE-2026-45447 is a heap use-after-free in PKCS7_verify(). These vulnerabilities collectively impact cryptographic operations and message processing in OpenSSL 3.

Potential Impact

The vulnerabilities can lead to denial-of-service conditions via resource exhaustion, memory corruption including heap buffer overflows and use-after-free, out-of-bounds memory reads, null pointer dereferences causing crashes, acceptance of forged cryptographic messages, and incorrect cryptographic processing potentially undermining message confidentiality and integrity. These issues affect the security and stability of applications relying on OpenSSL 3 for cryptographic functions.

Mitigation Recommendations

A security update for OpenSSL 3 has been released addressing these vulnerabilities. Users should apply the official OpenSSL 3 update provided by their vendor or distribution to remediate these issues. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor advisory for current remediation guidance and apply updates accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
SUSE-SU-2026:22132-1
Cve Count
11
Additional Cves
["CVE-2026-28390","CVE-2026-34180","CVE-2026-34182","CVE-2026-42766","CVE-2026-42770","CVE-2026-45445","CVE-2026-45446","CVE-2026-45447","CVE-2026-7383","CVE-2026-9076"]
State
PUBLISHED

Threat ID: 6abc27d5680226ef6846f988

Added to database: 09/29/2026, 21:04:21 UTC

Last enriched: 09/29/2026, 21:26:42 UTC

Last updated: 09/30/2026, 03:28:22 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses