SB2026090782 - SUSE update for openssl-3



SB2026090782 - SUSE update for openssl-3

Published: September 7, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026090782
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 60% Low 40%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Asymmetric Resource Consumption (Amplification) (CVE-ID: CVE-2026-54874)

CWE-ID: CWE-405 - Asymmetric Resource Consumption (Amplification)

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to asymmetric resource consumption in DTLS record buffering when receiving future-epoch records during a handshake in progress. A remote attacker can send numerous small forged DTLS records claiming to belong to the next epoch to cause a denial of service.

Up to 100 such records may be buffered per connection, retaining around 1.7 megabytes of memory because the implementation keeps the entire read buffer for each buffered record.


2) Out-of-bounds write (CVE-ID: CVE-2026-63072)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds write in OpenSSL CMS decryption key unwrapping logic when decrypting a crafted CMS message through CMS_decrypt(). A remote attacker can supply a crafted CMS message to cause a denial of service.

The issue causes a deterministic 8-byte heap write immediately past the allocation when the key-wrap OID is changed to select the padded variant.


3) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-63074)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in OpenSSL CMP extraCerts caching when processing rejected CMP messages containing additional certificates. A remote user can repeatedly send CMP requests with unique extra certificates to cause a denial of service.

The issue affects servers that reuse a single OSSL_CMP_CTX for the lifetime of the server process, allowing the untrusted certificate stack to grow without being expunged after message rejection.


4) NULL pointer dereference (CVE-ID: CVE-2026-63076)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper type validation leading to invalid pointer dereference in OpenSSL CMP password-based protection verification when processing a crafted protectionAlg parameter in a CMP message. A remote attacker can send a specially crafted CMP message to cause a denial of service.

CMP is a specialized feature that must be explicitly enabled, and on the client side exploitation is possible when communicating with a malicious or on-path CMP server.


5) Improper validation of integrity check value (CVE-ID: CVE-2026-75803)

CWE-ID: CWE-354 - Improper Validation of Integrity Check Value

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass integrity checks.

The vulnerability exists due to improper validation of integrity check value in EVP_Cipher() for ChaCha20-Poly1305 and AES-OCB when decrypting an empty ciphertext. A local user can provide a forged empty-ciphertext message with a supplied authentication tag to bypass integrity checks.

The issue occurs when applications use EVP_Cipher() and expect a successful return value to indicate that the AEAD tag was verified.


Remediation

Install update from vendor's website.