CVE-2026-41898

EUVD-2026-25587
rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
rust-openssl_projectrust-openssl
0.9.24 ≤
𝑥
< 0.10.78
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rust-openssl
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
vulnerable
forky
0.10.79-1
fixed
sid
0.10.79-1
fixed
trixie
no-dsa
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python311-cryptography
suse enterprise server 15 SP4
41.0.3-150400.16.25.1
fixed
suse enterprise server 15 SP5
41.0.3-150400.16.25.1
fixed
suse enterprise server 15 SP6
41.0.3-150600.23.9.1
fixed