Out-of-bounds write in OpenSSL - CVE-2026-63072
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in OpenSSL CMS decryption key unwrapping logic when decrypting a crafted CMS message through CMS_decrypt(). A remote attacker can supply a crafted CMS message to cause a denial of service.
The issue causes a deterministic 8-byte heap write immediately past the allocation when the key-wrap OID is changed to select the padded variant.
Affected software
Debian Linux
FreeBSD
openssl (Debian package)
How to mitigate CVE-2026-63072
openssl (Debian package) - update to 3.5.7-1~deb13u2