Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.
Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer. More typically such ASN.1 elements would instead be truncated.
An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.
Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.
The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensslUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-perl | Jun 16, 2026 | Jun 11, 2026 |
| Alpine Linux | — | Upgrade openssl | Jun 18, 2026 | Jun 9, 2026 |
| Amazon Linux Ami 2 | — | Upgrade openssl-perlUpgrade edk2-tools-docUpgrade edk2-ovmfUpgrade openssl-snapsafe-develUpgrade edk2-toolsUpgrade openssl-snapsafe-staticUpgrade openssl11Upgrade openssl11-libsUpgrade openssl11-develUpgrade openssl-snapsafe-debuginfoUpgrade opensslUpgrade openssl-libsUpgrade edk2-aarch64Upgrade openssl-staticUpgrade openssl11-debuginfoUpgrade openssl-develUpgrade openssl11-staticUpgrade openssl-snapsafe-perlUpgrade edk2-debuginfoUpgrade openssl-snapsafeUpgrade openssl-debuginfoUpgrade openssl-snapsafe-libs | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-snapsafe-libsUpgrade opensslUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade openssl-fips-provider-latestUpgrade openssl-perlUpgrade openssl-fips-provider-latest-debuginfoUpgrade openssl-libsUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-develUpgrade openssl-debuginfo | Jun 23, 2026 | Jun 9, 2026 |
| Debian | — | Upgrade openssl | Jun 16, 2026 | Jun 16, 2026 |
| Freebsd | — | Upgrade opensslUpgrade FreeBSDUpgrade openssl111Upgrade openssl34Upgrade openssl40Upgrade openssl36Upgrade openssl35 | Jun 15, 2026 | Jun 10, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Jun 10, 2026 | Jun 9, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory48 | Jul 22, 2026 | Jul 21, 2026 |
| Oracle Missing Cpu Jul 2026 | — | Apply the July 2026 Critical Patch Update (CPU) for Oracle Database | Jul 22, 2026 | Jun 9, 2026 |
| Redhat_linux | — | Upgrade opensslUpgrade openssl-debugsourceNo solution existsUpgrade openssl-libs-debuginfoUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-debuginfo | Jun 17, 2026 | Jun 9, 2026 |
| Rocky_linux | — | Upgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade openssl-debuginfoUpgrade openssl-develUpgrade opensslUpgrade openssl-perlUpgrade openssl-libs | Jun 17, 2026 | Jun 13, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.4.2Upgrade Splunk Enterprise to version 9.4.14Upgrade Splunk Enterprise to version 10.0.9Upgrade Splunk Enterprise to version 10.2.6 | Aug 20, 2026 | Jun 9, 2026 |
| Ubuntu | — | Upgrade openssl (Ubuntu Pro)Upgrade openssl1.0 (Ubuntu Pro)Upgrade opensslUpgrade libssl3Upgrade libssl3t64 | Jun 16, 2026 | Jun 9, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 17, 2026 | Jun 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub