Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.
Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.
CWE: CWE-787: Out-of-bounds Write
Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.
The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.
FIPS impact: no
As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 26, 2026 | Aug 25, 2026 |
| Debian | — | Upgrade openssl | Aug 26, 2026 | Aug 26, 2026 |
| Freebsd | — | Upgrade FreeBSDUpgrade openssl34Upgrade openssl40Upgrade openssl35Upgrade openssl36Upgrade openssl | Aug 26, 2026 | Aug 25, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Aug 27, 2026 | Aug 25, 2026 |
| Redhat_linux | — | Upgrade openssl-perlUpgrade opensslNo solution existsUpgrade openssl-libs-debuginfoUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-debuginfoUpgrade openssl-debugsource | Aug 27, 2026 | Aug 25, 2026 |
| Rocky_linux | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfo | Sep 17, 2026 | Sep 15, 2026 |
| Ubuntu | — | Upgrade opensslUpgrade openssl (Ubuntu Pro)Upgrade libssl3t64Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade openssl1.0 (Ubuntu Pro)Upgrade libssl3Upgrade libssl1.1 (Ubuntu Pro) | Aug 26, 2026 | Aug 25, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 21, 2026 | Aug 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub