openSUSE-SU-2026:21005-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21005-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21005-1
Upstream
CVE (15)
Related
Published
2026-06-22T12:26:17Z
Modified
2026-06-30T18:24:41Z
Summary
Security update for openssl-3
Details

This update for openssl-3 fixes the following issues

  • CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652).
  • CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340).
  • CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341).
  • CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342).
  • CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344).
  • CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345).
  • CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347).
  • CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349).
  • CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350).
  • CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351).
  • CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352).
  • CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353).
  • CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355).
  • CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356).
  • CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357).
References

Affected packages

openSUSE:Leap 16.0 / openssl-3

Package

Name
openssl-3
Purl
pkg:rpm/opensuse/openssl-3&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.5.0-160000.8.1

Ecosystem specific

{
    "binaries":  [
        {
            "libopenssl-3-devel":  "3.5.0-160000.8.1",
            "libopenssl-3-fips-provider":  "3.5.0-160000.8.1",
            "libopenssl-3-fips-provider-x86-64-v3":  "3.5.0-160000.8.1",
            "libopenssl3":  "3.5.0-160000.8.1",
            "libopenssl3-x86-64-v3":  "3.5.0-160000.8.1",
            "openssl-3":  "3.5.0-160000.8.1",
            "openssl-3-doc":  "3.5.0-160000.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21005-1.json"