Improper validation of integrity check value in OpenSSL - CVE-2026-75803
Published: August 26, 2026
Vulnerability details
The vulnerability allows a local user to bypass integrity checks.
The vulnerability exists due to improper validation of integrity check value in EVP_Cipher() for ChaCha20-Poly1305 and AES-OCB when decrypting an empty ciphertext. A local user can provide a forged empty-ciphertext message with a supplied authentication tag to bypass integrity checks.
The issue occurs when applications use EVP_Cipher() and expect a successful return value to indicate that the AEAD tag was verified.
Affected software
Debian Linux
openssl (Debian package)
How to mitigate CVE-2026-75803
openssl (Debian package) - update to 3.5.7-1~deb13u2