SB2026093079 - Multiple vulnerabilities in OpenSSL
Published: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 14 vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2026-72897)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in TLS certificate validity flag handling when processing peer signature algorithms after SSL_set_SSL_CTX() changes the connection context during a handshake. A remote attacker can offer provider signature algorithms to cause a denial of service.
The replacement context must know about more provider signature algorithms than the original context, and the affected algorithms are usable only with TLS 1.3.
2) Use-after-free (CVE-ID: CVE-2026-84783)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in the X.509 extension cache when several threads first decode extensions for the same shared certificate. A remote attacker can cause concurrent certificate-chain construction to cause a denial of service.
The affected certificate must be a trusted CA certificate shared between connections.
3) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-35189)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in relative CRL distribution point processing when caching X.509 extensions from a crafted certificate. A remote attacker can send a crafted certificate to cause a denial of service.
Multiple concurrent connections can produce similarly large memory allocations.
4) Expected behavior violation (CVE-ID: CVE-2026-35191)
CWE-ID: CWE-440 - Expected Behavior Violation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to amplify a distributed denial-of-service attack.
The vulnerability exists due to an expected behavior violation in the QUIC server unvalidated credit computation when processing a datagram containing multiple QUIC packets. A remote attacker can send a multi-packet QUIC datagram to amplify a distributed denial-of-service attack.
The server must be configured without client address validation.
5) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-42772)
CWE-ID: CWE-407 - Inefficient Algorithmic Complexity
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in QUIC stream fragment reassembly when handling out-of-order stream fragments. A remote user can manipulate stream fragment offsets to cause a denial of service.
Exploitation requires completion of the QUIC handshake and can use compliant STREAM frames within the advertised receive window.
6) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-54872)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to recover a private key.
The vulnerability exists due to an observable timing discrepancy in generic elliptic-curve scalar multiplication when performing ECDSA or SM2 signing with curves lacking dedicated implementations. A remote attacker can measure signing times across many signatures to recover a private key.
The timing signal is small and is most pronounced for curves whose group order lies on a machine-word boundary.
7) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-54873)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in QUIC stream fragment metadata handling when stream data remains in packet buffers pending application reads. A remote attacker can send crafted QUIC packets to cause a denial of service.
Packet-buffer retention time is controlled by the remote peer.
8) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-54875)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose secret scalar information.
The vulnerability exists due to an observable timing discrepancy in optimized SM2 scalar multiplication on ARM64 and RISC-V when performing SM2 signing or decryption. A remote attacker can measure operation times or observe cache-line access patterns to disclose secret scalar information.
The issue affects AArch64 and RISC-V platforms.
9) Out-of-bounds read (CVE-ID: CVE-2026-84782)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose heap memory contents or cause a denial of service.
The vulnerability exists due to an out-of-bounds read in OpenSSL DTLS retransmission handling when retransmitting a suspended DTLS handshake message write. A remote attacker can cause a suspended handshake message to be retransmitted to disclose heap memory contents or cause a denial of service.
Only applications that use DTLS are affected.
10) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-75804)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in QUIC connection-level stream flow control when receiving data across multiple streams. A remote attacker can send stream frames that remain within per-stream limits to cause a denial of service.
Exploitation requires opening several streams and omitting zero-offset bytes on each stream.
11) NULL pointer dereference (CVE-ID: CVE-2026-75805)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in CMP client revocation response handling when processing a crafted response to a revocation request based on a PKCS#10 CSR. A remote user can send a crafted revocation response to cause a denial of service.
The response must pass message-protection validation, and clients identifying the certificate by a certificate or issuer and serial number are not affected.
12) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-75806)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of specified quantity in input in DTLS 1.2 AEAD record processing when decrypting an unauthenticated record shorter than the explicit IV and authentication tag overhead. A remote attacker can send an undersized datagram to cause a denial of service.
The datagram must be routed to an existing DTLS 1.2 association using an AEAD cipher suite.
13) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-77696)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to recover a private key.
The vulnerability exists due to an observable timing discrepancy in SM2 signature generation when performing arithmetic on secret nonce and private-key values. A remote attacker can measure signing times across many signatures to recover a private key.
The issue affects SM2 signature generation on all platforms.
14) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-84784)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the QUIC RETIRE_CONNECTION_ID control frame queue when processing NEW_CONNECTION_ID frames without acknowledgements. A remote attacker can flood the connection with NEW_CONNECTION_ID frames and withhold acknowledgements to cause a denial of service.
The backlog consists of queued RETIRE_CONNECTION_ID control frames.
Remediation
Install update from vendor's website.