Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.
Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.
When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.
A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).
The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are affected by this issue.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensslUpgrade openssl-develUpgrade openssl-libsUpgrade openssl-perl | Jun 16, 2026 | Jun 11, 2026 |
| Alpine Linux | — | Upgrade openssl | Jun 18, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-libs-debuginfoUpgrade openssl-fips-provider-latest-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-snapsafe-libsUpgrade openssl-perlUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-libsUpgrade openssl-debugsourceUpgrade openssl-fips-provider-latestUpgrade openssl-devel | Jun 23, 2026 | Jun 9, 2026 |
| Debian | — | Upgrade openssl | Jun 16, 2026 | Jun 16, 2026 |
| Freebsd | — | Upgrade FreeBSDUpgrade openssl111Upgrade openssl34Upgrade openssl36Upgrade openssl40Upgrade opensslUpgrade openssl35 | Jun 15, 2026 | Jun 10, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Jun 10, 2026 | Jun 9, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory48 | Jul 22, 2026 | Jul 21, 2026 |
| Oracle Missing Cpu Jul 2026 | — | Apply the July 2026 Critical Patch Update (CPU) for Oracle Database | Jul 22, 2026 | Jun 9, 2026 |
| Redhat_linux | — | No solution existsUpgrade openssl-perlUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade openssl-libsUpgrade opensslUpgrade openssl-devel | Jun 17, 2026 | Jun 9, 2026 |
| Rocky_linux | — | Upgrade openssl-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade opensslUpgrade openssl-develUpgrade openssl-libsUpgrade openssl-perl | Jun 17, 2026 | Jun 13, 2026 |
| Ubuntu | — | Upgrade libssl3t64Upgrade libssl3Upgrade openssl | Jun 16, 2026 | Jun 9, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 17, 2026 | Jun 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub