CVE-2026-63072

EUVD-2026-65482
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based
on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive
can write and cleanse more bytes than that query reports, causing an 8-byte
out-of-bounds heap write.

Impact summary: An attacker who supplies a crafted CMS message can trigger a
deterministic 8-byte out-of-bounds heap write when the victim decrypts it
with CMS_decrypt(), corrupting the heap and typically resulting in a Denial
of Service.

CWE: CWE-787: Out-of-bounds Write

Description: The key-wrap OID is potentially attacker-controlled on the wire.
CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.
An attacker can take a legitimate message and change a single OID byte to
select the padded variant while leaving the message otherwise valid. Since
the unwrap key is derived from the recipient's private operation (ECDH key
agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot
pass, and the decryption fails with integrity failure.

The write is a fixed-size (8-byte), fixed-value (zero) heap overflow
immediately past the allocation, requires no special configuration, and is
reachable from the public CMS_decrypt() function. The consequence is
a heap corruption leading to a Denial of Service. The fix in the CMS code
sizes the unwrap output buffer for the worst case so a failed unwrap cannot
write past the allocation.

FIPS impact: no

As the CMS code lives outside the FIPS module boundary, no FIPS
modules are affected by this CVE.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58.98%
Affected Products (NVD)
VendorProductVersion
opensslopenssl
3.0.0 ≤
𝑥
< 3.0.22
opensslopenssl
3.4.0 ≤
𝑥
< 3.4.7
opensslopenssl
3.5.0 ≤
𝑥
< 3.5.8
opensslopenssl
3.6.0 ≤
𝑥
< 3.6.4
opensslopenssl
4.0.0 ≤
𝑥
< 4.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssl
bookworm
vulnerable
bookworm (security)
3.0.22-1~deb12u1
fixed
forky
3.6.4-1
fixed
sid
3.6.5-1
fixed
trixie
3.5.7-1~deb13u2
fixed
trixie (security)
3.5.7-1~deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssl
bionic
Fixed 1.1.1-1ubuntu2.1~18.04.23+esm10
released
focal
Fixed 1.1.1f-1ubuntu2.24+esm5
released
jammy
Fixed 3.0.2-0ubuntu1.29
released
noble
Fixed 3.0.13-0ubuntu3.15
released
resolute
Fixed 3.5.5-1ubuntu3.4
released
trusty
Fixed 1.0.1f-1ubuntu2.27+esm16
released
xenial
Fixed 1.0.2g-1ubuntu4.20+esm18
released
openssl-fips
jammy
dne
noble
Fixed 3.0.13-0ubuntu3.15+Fips1
released
resolute
dne
openssl1.0
bionic
Fixed 1.0.2n-1ubuntu5.13+esm6
released
jammy
dne
noble
dne
resolute
dne
nodejs
bionic
needs-triage
focal
not-affected
jammy
needed
noble
not-affected
resolute
not-affected
trusty
not-affected
xenial
needs-triage
edk2
bionic
Fixed 0~20180205.c0d9813c-2ubuntu0.3+esm3
released
focal
Fixed 0~20191122.bd85bf54-2ubuntu3.6+esm1
released
jammy
Fixed 2022.02-3ubuntu0.22.04.7
released
noble
Fixed 2024.02-2ubuntu0.10
released
resolute
Fixed 2025.11-3ubuntu7.3
released
xenial
not-affected
edk2-hwe
jammy
dne
noble
dne
resolute
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libopenssl-3-devel
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP4
3.0.8-150400.4.98.1
fixed
suse enterprise sap 15 SP5
3.0.8-150500.5.75.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP4
3.0.8-150400.4.98.1
fixed
suse enterprise server 15 SP5
3.0.8-150500.5.75.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
libopenssl-3-fips-provider
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
libopenssl-3-fips-provider-32bit
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
libopenssl3
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP4
3.0.8-150400.4.98.1
fixed
suse enterprise sap 15 SP5
3.0.8-150500.5.75.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP4
3.0.8-150400.4.98.1
fixed
suse enterprise server 15 SP5
3.0.8-150500.5.75.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
libopenssl3-32bit
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
openssl-3
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP4
3.0.8-150400.4.98.1
fixed
suse enterprise sap 15 SP5
3.0.8-150500.5.75.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP4
3.0.8-150400.4.98.1
fixed
suse enterprise server 15 SP5
3.0.8-150500.5.75.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.5.64.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssl
RHEL 9
1:3.5.8-1.el9_8
fixed
openssl-devel
RHEL 9
1:3.5.8-1.el9_8
fixed
openssl-libs
RHEL 9
1:3.5.8-1.el9_8
fixed
openssl-perl
RHEL 9
1:3.5.8-1.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
edk2-aarch64
Amazon Linux 2
0:20240813-313.amzn2
fixed
edk2-debuginfo
Amazon Linux 2
0:20240813-313.amzn2
fixed
edk2-ovmf
Amazon Linux 2
0:20240813-313.amzn2
fixed
edk2-tools
Amazon Linux 2
0:20240813-313.amzn2
fixed
edk2-tools-doc
Amazon Linux 2
0:20240813-313.amzn2
fixed
openssl
Amazon Linux 2
1:1.0.2k-24.amzn2.0.22
fixed
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-debuginfo
Amazon Linux 2
1:1.0.2k-24.amzn2.0.22
fixed
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-debugsource
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-devel
Amazon Linux 2
1:1.0.2k-24.amzn2.0.22
fixed
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-fips-provider-latest
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-fips-provider-latest-debuginfo
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-libs
Amazon Linux 2
1:1.0.2k-24.amzn2.0.22
fixed
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-libs-debuginfo
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-perl
Amazon Linux 2
1:1.0.2k-24.amzn2.0.22
fixed
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-snapsafe-libs
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-snapsafe-libs-debuginfo
Amazon Linux 2023
1:3.5.8-1.amzn2023.0.1
fixed
openssl-static
Amazon Linux 2
1:1.0.2k-24.amzn2.0.22
fixed
openssl11
Amazon Linux 2
1:1.1.1zi-1.amzn2.0.1
fixed
openssl11-debuginfo
Amazon Linux 2
1:1.1.1zi-1.amzn2.0.1
fixed
openssl11-devel
Amazon Linux 2
1:1.1.1zi-1.amzn2.0.1
fixed
openssl11-libs
Amazon Linux 2
1:1.1.1zi-1.amzn2.0.1
fixed
openssl11-static
Amazon Linux 2
1:1.1.1zi-1.amzn2.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
edk2
Azure Linux 3.0
0:20240524git3e722403cd16-19.azl3
fixed
openssl
Azure Linux 3.0
0:3.3.7-6.azl3
fixed