SB2026100273 - SUSE update for openssl-3
Published: October 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-35189)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in relative CRL distribution point processing when caching X.509 extensions from a crafted certificate. A remote attacker can send a crafted certificate to cause a denial of service.
Multiple concurrent connections can produce similarly large memory allocations.
2) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-54872)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to recover a private key.
The vulnerability exists due to an observable timing discrepancy in generic elliptic-curve scalar multiplication when performing ECDSA or SM2 signing with curves lacking dedicated implementations. A remote attacker can measure signing times across many signatures to recover a private key.
The timing signal is small and is most pronounced for curves whose group order lies on a machine-word boundary.
3) NULL pointer dereference (CVE-ID: CVE-2026-75805)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in CMP client revocation response handling when processing a crafted response to a revocation request based on a PKCS#10 CSR. A remote user can send a crafted revocation response to cause a denial of service.
The response must pass message-protection validation, and clients identifying the certificate by a certificate or issuer and serial number are not affected.
4) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-75806)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of specified quantity in input in DTLS 1.2 AEAD record processing when decrypting an unauthenticated record shorter than the explicit IV and authentication tag overhead. A remote attacker can send an undersized datagram to cause a denial of service.
The datagram must be routed to an existing DTLS 1.2 association using an AEAD cipher suite.
5) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-77696)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to recover a private key.
The vulnerability exists due to an observable timing discrepancy in SM2 signature generation when performing arithmetic on secret nonce and private-key values. A remote attacker can measure signing times across many signatures to recover a private key.
The issue affects SM2 signature generation on all platforms.
6) Out-of-bounds read (CVE-ID: CVE-2026-84782)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose heap memory contents or cause a denial of service.
The vulnerability exists due to an out-of-bounds read in OpenSSL DTLS retransmission handling when retransmitting a suspended DTLS handshake message write. A remote attacker can cause a suspended handshake message to be retransmitted to disclose heap memory contents or cause a denial of service.
Only applications that use DTLS are affected.
Remediation
Install update from vendor's website.