Search CVE reports
1 – 10 of 175 results
Some fixes available 4 of 9
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Not affected | Not affected |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Needs evaluation | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 4 of 9
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Not affected | Not affected |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Needs evaluation | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 1 of 5
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not in release | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 4 of 9
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Not affected | Not affected |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Needs evaluation | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 1 of 5
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not in release | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 9 of 19
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Fixed | Fixed |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Fixed |
| nodejs | Not affected | Not affected | Vulnerable | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 9 of 19
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Fixed | Fixed |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Fixed |
| nodejs | Not affected | Not affected | Vulnerable | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 1 of 5
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not in release | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 1 of 5
Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not in release | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 1 of 5
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not in release | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |