Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery. Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability. If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker. The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
{
"priority_reason": "OpenSSL developers have rated this as being low severity",
"binaries": [
{
"binary_name": "efi-shell-aa64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_version": "2025.02-8ubuntu3.1",
"binary_name": "efi-shell-arm"
},
{
"binary_name": "efi-shell-ia32",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "efi-shell-loongarch64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "efi-shell-riscv64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "efi-shell-x64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "ovmf",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_version": "2025.02-8ubuntu3.1",
"binary_name": "ovmf-ia32"
},
{
"binary_name": "ovmf-inteltdx",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "ovmf-legacy",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "qemu-efi-aarch64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "qemu-efi-arm",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "qemu-efi-loongarch64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "qemu-efi-riscv64",
"binary_version": "2025.02-8ubuntu3.1"
}
]
}
{
"priority_reason": "OpenSSL developers have rated this as being low severity",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "3.5.3-1ubuntu3.4",
"binary_name": "libssl3t64"
},
{
"binary_version": "3.5.3-1ubuntu3.4",
"binary_name": "openssl"
},
{
"binary_name": "openssl-provider-legacy",
"binary_version": "3.5.3-1ubuntu3.4"
}
]
}
{
"priority_reason": "OpenSSL developers have rated this as being low severity",
"binaries": [
{
"binary_name": "efi-shell-aa64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "efi-shell-loongarch64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_version": "2025.11-3ubuntu7",
"binary_name": "efi-shell-riscv64"
},
{
"binary_version": "2025.11-3ubuntu7",
"binary_name": "efi-shell-x64"
},
{
"binary_name": "ovmf",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_version": "2025.11-3ubuntu7",
"binary_name": "ovmf-amdsev"
},
{
"binary_version": "2025.11-3ubuntu7",
"binary_name": "ovmf-generic"
},
{
"binary_version": "2025.11-3ubuntu7",
"binary_name": "ovmf-inteltdx"
},
{
"binary_name": "ovmf-legacy",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "qemu-efi-aarch64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "qemu-efi-loongarch64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "qemu-efi-riscv64",
"binary_version": "2025.11-3ubuntu7"
}
]
}
{
"priority_reason": "OpenSSL developers have rated this as being low severity",
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libssl3t64",
"binary_version": "3.5.5-1ubuntu3.2"
},
{
"binary_name": "openssl",
"binary_version": "3.5.5-1ubuntu3.2"
},
{
"binary_version": "3.5.5-1ubuntu3.2",
"binary_name": "openssl-provider-legacy"
}
]
}