CVE-2026-41681
EUVD-2026-2558624.04.2026, 18:16
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the stack. This is reachable from safe Rust. This vulnerability is fixed in 0.10.78.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| rust-openssl_project | rust-openssl | 0.10.39 ≤ 𝑥 < 0.10.78 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References