OPENSUSE-SU-2026:21744-1
Vulnerability Summary
Timeline
Description
Security update for openssl-3 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837).
Affected Systems
- opensuse•openssl-3&distro=openSUSE Leap 16.0
< 3.5.0-160000.10.1
References (23)
- https://bugzilla.suse.com/1266343
- https://bugzilla.suse.com/1274774
- https://bugzilla.suse.com/1274777
- https://bugzilla.suse.com/1274788
- https://bugzilla.suse.com/1274790
- https://bugzilla.suse.com/1274791
- https://bugzilla.suse.com/1274792
- https://bugzilla.suse.com/1274795
- https://bugzilla.suse.com/1274796
- https://bugzilla.suse.com/1274797
- https://bugzilla.suse.com/1274798
- https://bugzilla.suse.com/1275837
- https://www.suse.com/security/cve/CVE-2026-14456
- https://www.suse.com/security/cve/CVE-2026-14457
- https://www.suse.com/security/cve/CVE-2026-18798
- https://www.suse.com/security/cve/CVE-2026-34181
- https://www.suse.com/security/cve/CVE-2026-54874
- https://www.suse.com/security/cve/CVE-2026-63072
- https://www.suse.com/security/cve/CVE-2026-63073
- https://www.suse.com/security/cve/CVE-2026-63074
- https://www.suse.com/security/cve/CVE-2026-63075
- https://www.suse.com/security/cve/CVE-2026-63076
- https://www.suse.com/security/cve/CVE-2026-75803