CVE-2026-63072

Source
https://cve.org/CVERecord?id=CVE-2026-63072
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63072.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-63072
Downstream
ALPINE (1)
AZL (3)
BELL (1)
CGA (14)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (2)
OESA (13)
openSUSE (2)
RHSA (4)
RLSA (2)
ROOT (4)
SUSE (21)
UBUNTU (1)
Related
Published
2026-08-25T12:59:34Z
Modified
2026-09-27T18:26:41Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Heap Buffer Overflow in CMS Key Unwrapping
Details

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.

Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.

CWE: CWE-787: Out-of-bounds Write

Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.

The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.

FIPS impact: no

As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

Database specific
{
    "cna_assigner": "openssl",
    "cwe_ids": [
        "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63072.json"
}
References

Affected packages

Git / github.com/openssl/openssl

Affected ranges

Type
GIT
Repo
https://github.com/openssl/openssl
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.0.22"
        },
        {
            "introduced": "3.4.0"
        },
        {
            "fixed": "3.4.7"
        },
        {
            "introduced": "3.5.0"
        },
        {
            "fixed": "3.5.8"
        },
        {
            "introduced": "3.6.0"
        },
        {
            "fixed": "3.6.4"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.0.2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.0-POST-CLANG-FORMAT-WEBKIT
3.0-PRE-CLANG-FORMAT-WEBKIT
3.4-POST-CLANG-FORMAT-WEBKIT
3.4-PRE-CLANG-FORMAT-WEBKIT
3.5-POST-CLANG-FORMAT-WEBKIT
3.5-PRE-CLANG-FORMAT-WEBKIT
3.6-POST-CLANG-FORMAT-WEBKIT
3.6-PRE-CLANG-FORMAT-WEBKIT
openssl-3.*
openssl-3.0.0
openssl-3.0.1
openssl-3.0.10
openssl-3.0.11
openssl-3.0.12
openssl-3.0.13
openssl-3.0.14
openssl-3.0.15
openssl-3.0.16
openssl-3.0.17
openssl-3.0.18
openssl-3.0.19
openssl-3.0.2
openssl-3.0.20
openssl-3.0.21
openssl-3.0.3
openssl-3.0.4
openssl-3.0.5
openssl-3.0.6
openssl-3.0.7
openssl-3.0.8
openssl-3.0.9
openssl-3.4.0
openssl-3.4.1
openssl-3.4.2
openssl-3.4.3
openssl-3.4.4
openssl-3.4.5
openssl-3.4.6
openssl-3.5.0
openssl-3.5.1
openssl-3.5.2
openssl-3.5.3
openssl-3.5.4
openssl-3.5.5
openssl-3.5.6
openssl-3.5.7
openssl-3.6.0
openssl-3.6.1
openssl-3.6.2
openssl-3.6.3
openssl-4.*
openssl-4.0.0
openssl-4.0.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63072.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "208136681009025530992181983177450609462",
                "67492296196001728152399820960887368767",
                "88888296945704491112425341945148345197",
                "77490842245204716087942480681456086748",
                "167791123496514995312111627585598185110",
                "58809577220617132767517088028514660857",
                "207631790121528015800023699476018421649",
                "256562552210483298504173461767217798440"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63072-055aceb1",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42",
        "target": {
            "file": "crypto/cms/cms_kari.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "208136681009025530992181983177450609462",
                "67492296196001728152399820960887368767",
                "86119493663496307471447645762303651773",
                "103971948677565821055656542659370118987",
                "34529704455751087727912697608663393448",
                "19398002998227456220659388596547811",
                "207631790121528015800023699476018421649",
                "256562552210483298504173461767217798440"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63072-08cbc8d9",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335",
        "target": {
            "file": "crypto/cms/cms_kari.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "190181369754425626514088426314121489343",
                "302983512749972924364577970277620573998",
                "300247287928641771380098240730580468045",
                "26618932074692139943363891828533656326",
                "137036785119351147396437308987354428173",
                "284265881093827514920610416597873339521",
                "207631790121528015800023699476018421649",
                "72083095091851580583601949470712484947"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63072-2eb41dcb",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756",
        "target": {
            "file": "crypto/cms/cms_kemri.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "316413486422965383581191612484836649227",
            "length": 1055
        },
        "id": "CVE-2026-63072-37741858",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756",
        "target": {
            "file": "crypto/cms/cms_kemri.c",
            "function": "cms_kek_cipher"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "316413486422965383581191612484836649227",
            "length": 1055
        },
        "id": "CVE-2026-63072-48232a5e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335",
        "target": {
            "file": "crypto/cms/cms_kemri.c",
            "function": "cms_kek_cipher"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "209945243013429542813762455339476825228",
            "length": 951
        },
        "id": "CVE-2026-63072-563f42ed",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382",
        "target": {
            "file": "crypto/cms/cms_kari.c",
            "function": "cms_kek_cipher"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "208136681009025530992181983177450609462",
                "67492296196001728152399820960887368767",
                "86119493663496307471447645762303651773",
                "103971948677565821055656542659370118987",
                "34529704455751087727912697608663393448",
                "19398002998227456220659388596547811",
                "207631790121528015800023699476018421649",
                "256562552210483298504173461767217798440"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63072-7dad758a",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756",
        "target": {
            "file": "crypto/cms/cms_kari.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "208136681009025530992181983177450609462",
                "67492296196001728152399820960887368767",
                "88888296945704491112425341945148345197",
                "77490842245204716087942480681456086748",
                "167791123496514995312111627585598185110",
                "58809577220617132767517088028514660857",
                "207631790121528015800023699476018421649",
                "256562552210483298504173461767217798440"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63072-8b81eab8",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a",
        "target": {
            "file": "crypto/cms/cms_kari.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "190181369754425626514088426314121489343",
                "302983512749972924364577970277620573998",
                "300247287928641771380098240730580468045",
                "26618932074692139943363891828533656326",
                "137036785119351147396437308987354428173",
                "284265881093827514920610416597873339521",
                "207631790121528015800023699476018421649",
                "72083095091851580583601949470712484947"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63072-947c82fa",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335",
        "target": {
            "file": "crypto/cms/cms_kemri.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "209945243013429542813762455339476825228",
            "length": 951
        },
        "id": "CVE-2026-63072-9fd87151",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42",
        "target": {
            "file": "crypto/cms/cms_kari.c",
            "function": "cms_kek_cipher"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "209945243013429542813762455339476825228",
            "length": 951
        },
        "id": "CVE-2026-63072-a9f7e2b1",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a",
        "target": {
            "file": "crypto/cms/cms_kari.c",
            "function": "cms_kek_cipher"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "208136681009025530992181983177450609462",
                "67492296196001728152399820960887368767",
                "88888296945704491112425341945148345197",
                "77490842245204716087942480681456086748",
                "167791123496514995312111627585598185110",
                "58809577220617132767517088028514660857",
                "207631790121528015800023699476018421649",
                "256562552210483298504173461767217798440"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63072-c1235256",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382",
        "target": {
            "file": "crypto/cms/cms_kari.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "115190944145237027672058340203765188425",
            "length": 980
        },
        "id": "CVE-2026-63072-dd096520",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756",
        "target": {
            "file": "crypto/cms/cms_kari.c",
            "function": "cms_kek_cipher"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "115190944145237027672058340203765188425",
            "length": 980
        },
        "id": "CVE-2026-63072-fd4e40aa",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335",
        "target": {
            "file": "crypto/cms/cms_kari.c",
            "function": "cms_kek_cipher"
        }
    }
]
vanir_signatures_modified
"2026-09-16T08:18:03Z"