It was discovered that OpenSSL incorrectly handled certain certificate revocation list distribution point names. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. (CVE-2026-35189)
It was discovered that OpenSSL incorrectly handled QUIC unvalidated amplification credit accounting. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-35191)
It was discovered that OpenSSL incorrectly implemented scalar multiplication for non-NIST elliptic curves. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. (CVE-2026-54872)
It was discovered that OpenSSL incorrectly implemented SM2 scalar multiplication on ARM64 and RISC-V architectures. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-54875)
It was discovered that OpenSSL incorrectly handled SSL context switching during a TLS handshake. An attacker could possibly use this issue to cause an out-of-bounds read, resulting in a denial of service or obtaining sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-72897)
It was discovered that OpenSSL incorrectly enforced QUIC connection- level flow control for streams. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-75804)
It was discovered that OpenSSL incorrectly handled a NULL pointer in CMP client revocation response processing. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-75805)
It was discovered that OpenSSL incorrectly handled undersized DTLS 1.2 AEAD records before authentication. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-75806)
It was discovered that OpenSSL incorrectly implemented SM2 signature generation. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. (CVE-2026-77696)
It was discovered that OpenSSL incorrectly handled DTLS retransmission of handshake messages. An attacker could possibly use this issue to cause incorrect handshake behavior or a denial of service. (CVE-2026-84782)
It was discovered that OpenSSL incorrectly handled QUIC RETIRE_CONNECTION_ID frames. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84784)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libssl3",
"binary_version": "3.0.2-0ubuntu1.30"
},
{
"binary_name": "openssl",
"binary_version": "3.0.2-0ubuntu1.30"
}
]
}
{
"cves": [
{
"id": "CVE-2026-35189",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-54872",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-75805",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-75806",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-77696",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-84782",
"severity": [
{
"score": "high",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8847-1.json"
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libssl3t64",
"binary_version": "3.0.13-0ubuntu3.16"
},
{
"binary_name": "openssl",
"binary_version": "3.0.13-0ubuntu3.16"
}
]
}
{
"cves": [
{
"id": "CVE-2026-35189",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-54872",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-75805",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-75806",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-77696",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-84782",
"severity": [
{
"score": "high",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:24.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8847-1.json"
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libssl3t64",
"binary_version": "3.5.5-1ubuntu3.6"
},
{
"binary_name": "openssl",
"binary_version": "3.5.5-1ubuntu3.6"
},
{
"binary_name": "openssl-provider-legacy",
"binary_version": "3.5.5-1ubuntu3.6"
}
]
}
{
"cves": [
{
"id": "CVE-2026-35189",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-35191",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-54872",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-54875",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-72897",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-75804",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-75805",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-75806",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-77696",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-84782",
"severity": [
{
"score": "high",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-84784",
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:26.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8847-1.json"