MGASA-2026-0253

Advisory lineage Upstream: 15 Downstream: 0
Published: 15 Jul 2026, 17:33
Last modified:15 Jul 2026, 17:49

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 Jul 2026, 17:33
Published
Vulnerability first disclosed
15 Jul 2026, 17:49
Last Modified
Vulnerability information updated

Description

Updated openssl packages fix security vulnerabilities The updated packages fix security vulnerabilities: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion. (CVE-2026-7383) Out-of-Bounds Read in CMS Password-Based Decryption. (CVE-2026-9076) Heap Buffer Over-read in ASN.1 Content Parsing. (CVE-2026-34180) PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys. (CVE-2026-34181) CMS AuthEnvelopedData Processing May Accept Forged Messages. (CVE-2026-34182) Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler. (CVE-2026-34183) NULL Pointer Dereference in QUIC Server Initial Packet Handling. (CVE-2026-42764) Possible NULL Dereference in Password-Based CMS Decryption. (CVE-2026-42766) NULL Pointer Dereference in CRMF EncryptedValue Decryption. (CVE-2026-42767) Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt(). (CVE-2026-42768) Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate. (CVE-2026-42769) FFC-DH Peer Validation Uses Attacker-Supplied q. (CVE-2026-42770) AES-OCB IV Ignored on EVP_Cipher() Path. (CVE-2026-45445) Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes. (CVE-2026-45446) Heap Use-After-Free in the PKCS7_verify(). (CVE-2026-45447)

Affected Systems

  • mageiaopenssl

    < 3.5.7-1.mga10

  • mageiaopenssl

    < 3.0.21-1.mga9

References (8)