Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.
Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.
When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.
Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.
OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl-develUpgrade openssl | Feb 3, 2026 | Jan 28, 2026 |
| Alpine Linux | — | Upgrade openssl | Jan 28, 2026 | Jan 27, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-develUpgrade openssl-snapsafe-libsUpgrade openssl-fips-provider-latestUpgrade openssl-debuginfoUpgrade aws-cfn-bootstrapUpgrade openssl-debugsourceUpgrade openssl-fips-provider-latest-debuginfoUpgrade openssl-libsUpgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-perl | Feb 10, 2026 | Jan 27, 2026 |
| Debian | — | Upgrade openssl | Jan 29, 2026 | Jan 29, 2026 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Apr 29, 2026 | Apr 28, 2026 |
| Freebsd | — | Upgrade openssl34Upgrade FreeBSDUpgrade mysql80-serverUpgrade mysql84-clientUpgrade mysql96-serverUpgrade mysql96-clientUpgrade mysql80-clientUpgrade opensslUpgrade openssl35Upgrade mysql84-serverUpgrade openssl36Upgrade openssl33 | May 19, 2026 | May 19, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jan 27, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory46 | Mar 10, 2026 | Mar 9, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | May 12, 2026 |
| Oracle Missing Cpu Apr 2026 | — | Apply the April 2026 Critical Patch Update (CPU) for Oracle Database | Apr 22, 2026 | Apr 14, 2026 |
| Oracle Mysql | — | Upgrade to MySQL version 9.7.0Upgrade to MySQL version 8.4.9Upgrade to MySQL version 8.0.46 | Apr 22, 2026 | Jan 27, 2026 |
| Oracle_linux | — | Upgrade openssl-develUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl | Jan 30, 2026 | Jan 27, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Jan 27, 2026 |
| Redhat_linux | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfo | Jan 29, 2026 | Jan 27, 2026 |
| Rocky_linux | — | Upgrade openssl-debuginfoUpgrade opensslUpgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade openssl-develUpgrade openssl-libsUpgrade openssl-perl | Feb 2, 2026 | Jan 30, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.4.9Upgrade Splunk Enterprise to version 10.2.1Upgrade Splunk Universal Forwarder to version 10.0.4Upgrade Splunk Enterprise to version 10.0.4Upgrade Splunk Universal Forwarder to version 10.2.1Upgrade Splunk Enterprise to version 9.3.10 | Jul 30, 2026 | Jan 27, 2026 |
| Ubuntu | — | Upgrade opensslUpgrade libssl3t64Upgrade libssl3 | Jan 28, 2026 | Jan 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub