[ubuntu/jammy-security] openssl 3.0.2-0ubuntu1.25 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Tue Jun 9 16:52:59 UTC 2026
openssl (3.0.2-0ubuntu1.25) jammy-security; urgency=medium
* SECURITY UPDATE: Heap Buffer Over-read in ASN.1 Content Parsing
- debian/patches/CVE-2026-34180.patch: Avoid length truncation in
ASN1_STRING_set in crypto/asn1/tasn_dec.c.
- CVE-2026-34180
* SECURITY UPDATE: CMS AuthEnvelopedData Processing May Accept Forged Messages
- debian/patches/CVE-2026-34182-pre1.patch: Ensure
ossl_cms_EncryptedContent_init_bio() reports an error on no OID in
crypto/cms/cms_enc.c, crypto/cms/cms_err.c, crypto/err/openssl.txt,
include/openssl/cmserr.h.
- debian/patches/CVE-2026-34182-1.patch: CMS: Produce error when AEAD
algorithms are used in enveloped data in crypto/cms/cms_enc.c,
crypto/cms/cms_env.c, crypto/cms/cms_err.c, crypto/cms/cms_local.h,
crypto/err/openssl.txt, include/openssl/cmserr.h, test/cms-msg/enveloped-
content-type-for-aes-gcm.pem, test/cmsapitest.c,
test/recipes/80-test_cms.t.
- debian/patches/CVE-2026-34182-2.patch: Reject potentially forged encrypted
CMS AuthEnvelopedData messages in crypto/cms/cms_enc.c.
- debian/patches/CVE-2026-34182-3.patch: Add tests for CVE-2026-34182 in
test/cmsapitest.c.
- CVE-2026-34182
* SECURITY UPDATE: Possible NULL Dereference in Password-Based CMS Decryption
- debian/patches/CVE-2026-42766.patch: Fix potential NULL dereference
processing CMS PasswordRecipientInfo in crypto/cms/cms_pwri.c.
- CVE-2026-42766
* SECURITY UPDATE: NULL Pointer Dereference in CRMF EncryptedValue Decryption
- debian/patches/CVE-2026-42767.patch: Fix potential NULL dereference in
OSSL_CRMF_ENCRYPTEDVALUE_decrypt() in crypto/crmf/crmf_lib.c.
- CVE-2026-42767
* SECURITY UPDATE: FFC-DH Peer Validation Uses Attacker-Supplied q
- debian/patches/CVE-2026-42770.patch: Match the local q DHX parameter
against the peer's q in providers/implementations/exchange/dh_exch.c.
- CVE-2026-42770
* SECURITY UPDATE: AES-OCB IV Ignored on EVP_Cipher() Path
- debian/patches/CVE-2026-45445.patch: Apply the buffered IV on the AES-OCB
EVP_Cipher() path in providers/implementations/ciphers/cipher_aes_ocb.c,
test/evp_extra_test.c.
- CVE-2026-45445
* SECURITY UPDATE: Incorrect Tag Processing for Empty Messages in
AES-GCM-SIV and AES-SIV modes
- debian/patches/CVE-2026-45446.patch: Fix handling of empty-ciphertext
messages in AES-SIV in providers/implementations/ciphers/cipher_aes_siv.c,
test/evp_extra_test.c.
- CVE-2026-45446
* SECURITY UPDATE: Heap Use-After-Free in OpenSSL PKCS7_verify()
- debian/patches/CVE-2026-45447-pre1.patch: Revert unnecessary
PKCS7_verify() performance optimization in crypto/pkcs7/pk7_smime.c.
- debian/patches/CVE-2026-45447-1.patch: Fix possible use-after-free in
OpenSSL PKCS7_verify() in crypto/pkcs7/pk7_smime.c.
- debian/patches/CVE-2026-45447-2.patch: Test for CVE-2026-45447 (UAF in
PKCS7_verify) in test/recipes/80-test_cms.t, test/smime-eml/pkcs7-empty-
digest-set.eml.
- CVE-2026-45447
* SECURITY UPDATE: Possible Heap Buffer Overflow in ASN.1 Multibyte String
Conversion
- debian/patches/CVE-2026-7383.patch: Reject oversized inputs in
ASN1_mbstring_ncopy() in crypto/asn1/a_mbstr.c.
- CVE-2026-7383
* SECURITY UPDATE: Out-of-Bounds Read in CMS Password-Based Decryption
- debian/patches/CVE-2026-9076.patch: cms: kek_unwrap_key: Fix out-of-bounds
read in check-byte validation in crypto/cms/cms_pwri.c.
- CVE-2026-9076
Date: 2026-06-08 21:50:11.841830+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.25
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list