<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:56:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:6224 — Moderate: openssl security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:6224</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.
Security Fix(es):
* openssl: c_rehash script allows command injection (CVE-2022-1292)
* openssl: Signer certificate verification returns inaccurate response when using OCSP_NOCHECKS (CVE-2022-1343)
* openssl: OPENSSL_LH_flush() breaks reuse of memory (CVE-2022-1473)
* openssl: the c_rehash script allows command injection (CVE-2022-2068)
* openssl: AES OCB fails to encrypt some bytes (CVE-2022-2097)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* openssl occasionally sends internal error to gnutls when using FFDHE (BZ#2080323)
* openssl req defaults to 3DES (BZ#2085499)
* OpenSSL accepts custom elliptic curve parameters when p is large [almalinux-9] (BZ#2085508)
* OpenSSL mustn&amp;#39;t work with ECDSA with explicit curve parameters in FIPS mode (BZ#2085521)
* openssl s_server -groups secp256k1 in FIPS fails because X25519/X448 (BZ#2086554)
* Converting FIPS power-on self test to KAT (BZ#2086866)
* Small RSA keys work for some operations in FIPS mode (BZ#2091938)
* FIPS provider doesn&amp;#39;t block RSA encryption for key transport (BZ#2091977)
* OpenSSL testsuite certificates expired (BZ#2095696)
* [IBM 9.1 HW OPT] POWER10 performance enhancements for cryptogr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.
Security Fix(es):
* openssl: c_rehash script allows command injection (CVE-2022-1292)
* openssl: Signer certificate verification returns inaccurate response when using OCSP_NOCHECKS (CVE-2022-1343)
* openssl: OPENSSL_LH_flush() breaks reuse of memory (CVE-2022-1473)
* openssl: the c_rehash script allows command injection (CVE-2022-2068)
* openssl: AES OCB fails to encrypt some bytes (CVE-2022-2097)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* openssl occasionally sends internal error to gnutls when using FFDHE (BZ#2080323)
* openssl req defaults to 3DES (BZ#2085499)
* OpenSSL accepts custom elliptic curve parameters when p is large [almalinux-9] (BZ#2085508)
* OpenSSL mustn&amp;#39;t work with ECDSA with explicit curve parameters in FIPS mode (BZ#2085521)
* openssl s_server -groups secp256k1 in FIPS fails because X25519/X448 (BZ#2086554)
* Converting FIPS power-on self test to KAT (BZ#2086866)
* Small RSA keys work for some operations in FIPS mode (BZ#2091938)
* FIPS provider doesn&amp;#39;t block RSA encryption for key transport (BZ#2091977)
* OpenSSL testsuite certificates expired (BZ#2095696)
* [IBM 9.1 HW OPT] POWER10 performance enhancements for cryptogr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:6224</guid>
    </item>
    <item>
      <title>bdu:2022-03175</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-03175</link>
      <description>bdu:2022-03175</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-03175</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-1343 — CVE-2022-1343 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-1343</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-1343</guid>
    </item>
    <item>
      <title>certfr-2022-avi-411 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines
d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-411</link>
      <description>certfr-2022-avi-411</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-411</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</guid>
    </item>
    <item>
      <title>cnvd-2022-37789</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-37789</link>
      <description>cnvd-2022-37789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-37789</guid>
    </item>
    <item>
      <title>EUVD-2026-237461</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237461</link>
      <description>EUVD-2026-237461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237461</guid>
    </item>
    <item>
      <title>fkie_cve-2022-1343</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1343</link>
      <description>&lt;p&gt;The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL &amp;#34;ocsp&amp;#34; application. When verifying an ocsp response with the &amp;#34;-no_cert_checks&amp;#34; option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL &amp;#34;ocsp&amp;#34; application. When verifying an ocsp response with the &amp;#34;-no_cert_checks&amp;#34; option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-1343</guid>
    </item>
    <item>
      <title>GHSA-mfm6-r9g2-q4r7 — `OCSP_basic_verify` may incorrectly verify the response signing certificate</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mfm6-r9g2-q4r7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL &amp;#34;ocsp&amp;#34; application. When verifying an ocsp response with the &amp;#34;-no_cert_checks&amp;#34; option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL &amp;#34;ocsp&amp;#34; application. When verifying an ocsp response with the &amp;#34;-no_cert_checks&amp;#34; option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mfm6-r9g2-q4r7</guid>
    </item>
    <item>
      <title>gsd-2022-1343</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-1343</link>
      <description>gsd-2022-1343</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-1343</guid>
    </item>
    <item>
      <title>ICSA-23-047-03 — Siemens Brownfield Connectivity Client</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-047-03</link>
      <description>&lt;p&gt;The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. Under certain circumstances, the command line OCSP verify function reports successful verification when the varification in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. When using the RC4-MD5 ciphersuite, which is disabled by default, an attacker is able to modify data in transit due to an incorrect use of the AAD data as the MAC key in OpenSSL 3.0. An attacker is not able to decrypt any communication. The used OpenSSL version improperly reuses memory when decoding certificates or keys. This can lead to a process termination and Denial of Service for long lived processes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. Under certain circumstances, the command line OCSP verify function reports successful verification when the varification in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. When using the RC4-MD5 ciphersuite, which is disabled by default, an attacker is able to modify data in transit due to an incorrect use of the AAD data as the MAC key in OpenSSL 3.0. An attacker is not able to decrypt any communication. The used OpenSSL version improperly reuses memory when decoding certificates or keys. This can lead to a process termination and Denial of Service for long lived processes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-047-03</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12204-1 — libopenssl-3-devel-3.0.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12204-1</link>
      <description>&lt;p&gt;libopenssl-3-devel-3.0.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-3-devel-3.0.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12204-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2022-0027 — `OCSP_basic_verify` may incorrectly verify the response signing certificate</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2022-0027</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;The function `OCSP_basic_verify` verifies the signer certificate on an OCSP
response. In the case where the (non-default) flag OCSP_NOCHECKS is used then
the response will be positive (meaning a successful verification) even in the
case where the response signing certificate fails to verify.&lt;/p&gt;
&lt;p&gt;It is anticipated that most users of `OCSP_basic_verify` will not use the
OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return
a negative value (indicating a fatal error) in the case of a certificate
verification failure. The normal expected return value in this case would be 0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;The function `OCSP_basic_verify` verifies the signer certificate on an OCSP
response. In the case where the (non-default) flag OCSP_NOCHECKS is used then
the response will be positive (meaning a successful verification) even in the
case where the response signing certificate fails to verify.&lt;/p&gt;
&lt;p&gt;It is anticipated that most users of `OCSP_basic_verify` will not use the
OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return
a negative value (indicating a fatal error) in the case of a certificate
verification failure. The normal expected return value in this case would be 0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2022-0027</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-1343</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1343</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL &amp;#34;ocsp&amp;#34; application. When verifying an ocsp response with the &amp;#34;-no_cert_checks&amp;#34; option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL &amp;#34;ocsp&amp;#34; application. When verifying an ocsp response with the &amp;#34;-no_cert_checks&amp;#34; option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1343</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0071 — OpenSSL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0071</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0071</guid>
    </item>
  </channel>
</rss>
