MGASA-2026-0353
Vulnerability Summary
Timeline
Description
Updated openssl packages fix security vulnerabilities Unbounded Memory Growth in QUIC Server Incoming Channel Queue. (CVE-2026-14456) QUIC Server May Trigger Double Free When Processing INITIAL Packet. (CVE-2026-18798) Heap Buffer Overflow in CMS Key Unwrapping. (CVE-2026-63072) Invalid Pointer Dereference in CMP Server via Crafted protectionAlg. (CVE-2026-63076) RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate. (CVE-2026-14457) Excessive Memory Use Buffering DTLS Records for a Future Epoch. (CVE-2026-54874) Untrusted Sender DN Used as Format String in CMP Response Validation. (CVE-2026-63073) CMP Indefinite Cache Growth of ExtraCerts. (CVE-2026-63074) QUIC ACK-only Packet Retention Can Cause Memory Exhaustion. (CVE-2026-63075)
Affected Systems
- mageia•openssl
< 3.5.8-1.mga10
- mageia•openssl
< 3.0.22-1.mga9
References (7)
- https://advisories.mageia.org/MGASA-2026-0353.html
- https://bugs.mageia.org/show_bug.cgi?id=36139
- https://www.openwall.com/lists/oss-security/2026/08/13/4
- https://openssl-library.org/news/secadv/20260813.txt
- https://www.openwall.com/lists/oss-security/2026/08/25/3
- https://openssl-library.org/news/secadv/20260825.txt
- https://lists.debian.org/debian-security-announce/2026/msg00376.html