openssl-3.5.5-3.el9_8.ML.1
エラータID: AXSA:2026-1317:13
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.
Security Fix(es):
* openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-28390
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
Update packages.
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
N/A
SRPMS
- openssl-3.5.5-3.el9_8.ML.1.src.rpm
MD5: b9bfc2025e69ac2dd10e5474208ce791
SHA-256: 634248ec647364fd5a0ccc118358720faf8af6bbab707b241851eea157d026b8
Size: 50.85 MB
Asianux Server 9 for x86_64
- openssl-3.5.5-3.el9_8.ML.1.x86_64.rpm
MD5: 4b6b5514d1894d757f7af37b746118d8
SHA-256: d3381f75763d8a5b9d8e047d07e48905bbb57b113a218e521a02da5d0a7a75d2
Size: 1.46 MB - openssl-devel-3.5.5-3.el9_8.ML.1.i686.rpm
MD5: 15f4b32b5c13356ae34b7b8d9d95d202
SHA-256: 8c3150257f4d227719898d65142d5a8bdd4b16dead4634d9a62cac385e82afe8
Size: 3.62 MB - openssl-devel-3.5.5-3.el9_8.ML.1.x86_64.rpm
MD5: 73a9e13360d21d11cc590afc6c6e50df
SHA-256: 444277bee46b69f348331dc26ca1b124f99b5587a26e4b011fe7d30ada2afab8
Size: 3.62 MB - openssl-fips-provider-3.5.5-3.el9_8.ML.1.i686.rpm
MD5: 1cfeb64bde39b782fac5492c2dfbc9e1
SHA-256: 1e4df9bc7b9d06028bbbf074c5c2a8c06ad5a09a3881ff81ae743533401733d0
Size: 704.12 kB - openssl-fips-provider-3.5.5-3.el9_8.ML.1.x86_64.rpm
MD5: 182fa25176fdae57b7ef8d3641a1b8d7
SHA-256: 400f631736e31aaddaae8d59aa55188976c0486eaec177c0c0b3ab7472d80a3e
Size: 811.90 kB - openssl-libs-3.5.5-3.el9_8.ML.1.i686.rpm
MD5: 8e923c46465484c3e5cd50442126aded
SHA-256: 723064fde3c52c850f5adb9268441ac93173b917c99e427aae5dd948d9fd3084
Size: 2.29 MB - openssl-libs-3.5.5-3.el9_8.ML.1.x86_64.rpm
MD5: 236ece7f4c5ed8a1833d531dc56961e2
SHA-256: 9c4d0b8527bf74b37aec8c43c2cc1ff5044a50316140c79cff46cec6a6ab7b4a
Size: 2.30 MB - openssl-perl-3.5.5-3.el9_8.ML.1.x86_64.rpm
MD5: d8e7b54238d2d0397e6311fdfe63085b
SHA-256: 55a3813f39778bb2a22ed15cc159622b845a2ad0ec1e63c0c5c90450d37edd2b
Size: 27.76 kB