Search CVE reports


Toggle filters

41 – 50 of 347 results


CVE-2026-41678

Medium priority
Vulnerable

rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Vulnerable Vulnerable Vulnerable Not affected —
Show less packages

CVE-2026-41677

Medium priority
Vulnerable

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Vulnerable Vulnerable Vulnerable Vulnerable —
Show less packages

CVE-2026-41676

Medium priority
Vulnerable

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Vulnerable Vulnerable Vulnerable Vulnerable —
Show less packages

CVE-2026-31790

Medium priority

Some fixes available 5 of 9

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain...

6 affected packages

openssl-fips, edk2, edk2-hwe, nodejs, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
edk2 Vulnerable Vulnerable Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
nodejs Not affected Not affected Not affected Not affected Not affected
openssl Fixed Fixed Fixed Not affected Not affected
openssl1.0 Not in release Not in release Not in release — Not affected
Show less packages

CVE-2026-31789

Low priority

Some fixes available 5 of 9

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker...

6 affected packages

openssl-fips, edk2, edk2-hwe, nodejs, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
edk2 Vulnerable Vulnerable Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
nodejs Not affected Not affected Not affected Not affected Not affected
openssl Fixed Fixed Fixed Not affected Not affected
openssl1.0 Not in release Not in release Not in release — Not affected
Show less packages

CVE-2026-28390

Low priority

Some fixes available 9 of 20

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-28389

Low priority

Some fixes available 9 of 20

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-28388

Low priority

Some fixes available 10 of 21

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-28387

Low priority

Some fixes available 7 of 18

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Not affected
Show less packages

CVE-2026-28386

Low priority
Not affected

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 — Not affected Not affected Not affected Not affected
nodejs — Not affected Not affected Not affected Not affected
openssl — Not affected Not affected Not affected Not affected
openssl-fips — Not affected Not affected — —
openssl1.0 — Not in release Not in release — Not affected
Show less packages