Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.
Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.
When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.
Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.
OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensslUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libs | Feb 3, 2026 | Jan 28, 2026 |
| Alpine Linux | — | Upgrade openssl | Jan 28, 2026 | Jan 27, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-fips-provider-latest-debuginfoUpgrade openssl-libsUpgrade openssl-perlUpgrade opensslUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl-fips-provider-latestUpgrade openssl-debuginfoUpgrade openssl-snapsafe-libsUpgrade aws-cfn-bootstrapUpgrade openssl-develUpgrade openssl-debugsource | Feb 10, 2026 | Jan 27, 2026 |
| Debian | — | Upgrade openssl | Jan 29, 2026 | Jan 29, 2026 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Apr 29, 2026 | Apr 28, 2026 |
| Freebsd | — | Upgrade openssl35Upgrade opensslUpgrade openssl33Upgrade openssl36Upgrade mysql84-serverUpgrade mysql84-clientUpgrade mysql96-clientUpgrade mysql80-clientUpgrade FreeBSDUpgrade openssl34Upgrade mysql96-serverUpgrade mysql80-server | May 19, 2026 | May 19, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jan 27, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory46 | Mar 10, 2026 | Mar 9, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | May 12, 2026 |
| Oracle Missing Cpu Apr 2026 | — | Apply the April 2026 Critical Patch Update (CPU) for Oracle Database | Apr 22, 2026 | Apr 14, 2026 |
| Oracle Mysql | — | Upgrade to MySQL version 8.4.9Upgrade to MySQL version 8.0.46Upgrade to MySQL version 9.7.0 | Apr 22, 2026 | Jan 27, 2026 |
| Oracle_linux | — | Upgrade openssl-develUpgrade openssl-libsUpgrade opensslUpgrade openssl-perl | Jan 30, 2026 | Jan 27, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Jan 27, 2026 |
| Redhat_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-libsUpgrade openssl-libs-debuginfoUpgrade openssl-develUpgrade openssl-debugsource | Jan 29, 2026 | Jan 27, 2026 |
| Rocky_linux | — | Upgrade openssl-libsUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade opensslUpgrade openssl-debuginfo | Feb 2, 2026 | Jan 30, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.3.10Upgrade Splunk Universal Forwarder to version 10.2.1Upgrade Splunk Universal Forwarder to version 10.0.4Upgrade Splunk Enterprise to version 10.0.4Upgrade Splunk Enterprise to version 9.4.9Upgrade Splunk Enterprise to version 10.2.1 | Jul 30, 2026 | Jan 27, 2026 |
| Ubuntu | — | Upgrade libssl3Upgrade libssl3t64Upgrade openssl | Jan 28, 2026 | Jan 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub