<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:05:38 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67154 — Important: openssl security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67154</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)
  * openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)
  * openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)
  * openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)
  * openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)
  * openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)
  * openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)
  * openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)
  * openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [AlmaLinux 10.2.z] (JIRA:AlmaLinux-212362)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)
  * openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)
  * openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)
  * openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)
  * openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)
  * openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)
  * openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)
  * openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)
  * openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [AlmaLinux 10.2.z] (JIRA:AlmaLinux-212362)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67154</guid>
    </item>
    <item>
      <title>bdu:2026-14720</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14720</link>
      <description>bdu:2026-14720</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14720</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-54874</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-54874</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssl, Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssl, Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-54874</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1079 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Elles permettent à un attaquant de provoquer un déni de s…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1079</link>
      <description>certfr-2026-avi-1079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1079</guid>
    </item>
    <item>
      <title>EUVD-2026-358665</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358665</link>
      <description>EUVD-2026-358665</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358665</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54874</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54874</link>
      <description>&lt;p&gt;Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.&lt;/p&gt;
&lt;p&gt;Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large amount of memory,
which may lead to a Denial of Service.&lt;/p&gt;
&lt;p&gt;CWE: CWE-405: Asymmetric Resource Consumption (Amplification)&lt;/p&gt;
&lt;p&gt;Description: While a DTLS handshake is in progress, a peer may legitimately
have already moved on to the next epoch (for example, having sent its
ChangeCipherSpec and Finished messages) before the local endpoint has
processed the same transition, typically because of reordering on the
underlying UDP transport. OpenSSL buffers such early records so that they
can be processed once the local endpoint catches up.&lt;/p&gt;
&lt;p&gt;Buffering a record currently retains the entire read buffer it arrived in,
which is sized to hold the largest possible DTLS record (around 16
kilobytes), rather than just the bytes that make up the record itself. Up
to 100 such records may be buffered per connection. As a result, a peer
that sends a stream of small forged records claiming to belong to the next
epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of
memory, despite sending only a small fraction of that amount of data over
the network.&lt;/p&gt;
&lt;p&gt;An attacker therefore gains a memory amplification factor of around 1200,
and can multiply the effect across as many associations as it is a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.&lt;/p&gt;
&lt;p&gt;Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large amount of memory,
which may lead to a Denial of Service.&lt;/p&gt;
&lt;p&gt;CWE: CWE-405: Asymmetric Resource Consumption (Amplification)&lt;/p&gt;
&lt;p&gt;Description: While a DTLS handshake is in progress, a peer may legitimately
have already moved on to the next epoch (for example, having sent its
ChangeCipherSpec and Finished messages) before the local endpoint has
processed the same transition, typically because of reordering on the
underlying UDP transport. OpenSSL buffers such early records so that they
can be processed once the local endpoint catches up.&lt;/p&gt;
&lt;p&gt;Buffering a record currently retains the entire read buffer it arrived in,
which is sized to hold the largest possible DTLS record (around 16
kilobytes), rather than just the bytes that make up the record itself. Up
to 100 such records may be buffered per connection. As a result, a peer
that sends a stream of small forged records claiming to belong to the next
epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of
memory, despite sending only a small fraction of that amount of data over
the network.&lt;/p&gt;
&lt;p&gt;An attacker therefore gains a memory amplification factor of around 1200,
and can multiply the effect across as many associations as it is a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54874</guid>
    </item>
    <item>
      <title>GHSA-97g4-hhwh-c697</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-97g4-hhwh-c697</link>
      <description>&lt;p&gt;Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.&lt;/p&gt;
&lt;p&gt;Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large amount of memory,
which may lead to a Denial of Service.&lt;/p&gt;
&lt;p&gt;CWE: CWE-405: Asymmetric Resource Consumption (Amplification)&lt;/p&gt;
&lt;p&gt;Description: While a DTLS handshake is in progress, a peer may legitimately
have already moved on to the next epoch (for example, having sent its
ChangeCipherSpec and Finished messages) before the local endpoint has
processed the same transition, typically because of reordering on the
underlying UDP transport. OpenSSL buffers such early records so that they
can be processed once the local endpoint catches up.&lt;/p&gt;
&lt;p&gt;Buffering a record currently retains the entire read buffer it arrived in,
which is sized to hold the largest possible DTLS record (around 16
kilobytes), rather than just the bytes that make up the record itself. Up
to 100 such records may be buffered per connection. As a result, a peer
that sends a stream of small forged records claiming to belong to the next
epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of
memory, despite sending only a small fraction of that amount of data over
the network.&lt;/p&gt;
&lt;p&gt;An attacker therefore gains a memory amplification factor of around 1200,
and can multiply the effect across as many associations as it is a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.&lt;/p&gt;
&lt;p&gt;Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large amount of memory,
which may lead to a Denial of Service.&lt;/p&gt;
&lt;p&gt;CWE: CWE-405: Asymmetric Resource Consumption (Amplification)&lt;/p&gt;
&lt;p&gt;Description: While a DTLS handshake is in progress, a peer may legitimately
have already moved on to the next epoch (for example, having sent its
ChangeCipherSpec and Finished messages) before the local endpoint has
processed the same transition, typically because of reordering on the
underlying UDP transport. OpenSSL buffers such early records so that they
can be processed once the local endpoint catches up.&lt;/p&gt;
&lt;p&gt;Buffering a record currently retains the entire read buffer it arrived in,
which is sized to hold the largest possible DTLS record (around 16
kilobytes), rather than just the bytes that make up the record itself. Up
to 100 such records may be buffered per connection. As a result, a peer
that sends a stream of small forged records claiming to belong to the next
epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of
memory, despite sending only a small fraction of that amount of data over
the network.&lt;/p&gt;
&lt;p&gt;An attacker therefore gains a memory amplification factor of around 1200,
and can multiply the effect across as many associations as it is a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-97g4-hhwh-c697</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-54874 — Excessive Memory Use Buffering DTLS Records for a Future Epoch</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-54874</link>
      <description>msrc_CVE-2026-54874</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-54874</guid>
    </item>
    <item>
      <title>OESA-2026-3819 — compat-openssl11 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3819</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: compat-openssl11&lt;/p&gt;
&lt;p&gt;OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.&lt;/p&gt;
&lt;p&gt;Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large amount of memory,
which may lead to a Denial of Service.&lt;/p&gt;
&lt;p&gt;CWE: CWE-405: Asymmetric Resource Consumption (Amplification)&lt;/p&gt;
&lt;p&gt;Description: While a DTLS handshake is in progress, a peer may legitimately
have already moved on to the next epoch (for example, having sent its
ChangeCipherSpec and Finished messages) before the local endpoint has
processed the same transition, typically because of reordering on the
underlying UDP transport. OpenSSL buffers such early records so that they
can be processed once the local endpoint catches up.&lt;/p&gt;
&lt;p&gt;Buffering a record currently retains the entire read buffer it arrived in,
which is sized to hold the largest possible DTLS record (around 16
kilobytes), rather than just the bytes that make up the record itself. Up
to 100 such records may be buffered per connection. As a result, a peer
that sends a stream of small forged records claiming to belong to the next
epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of
memory, despite sending only a small fraction of that amount…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: compat-openssl11&lt;/p&gt;
&lt;p&gt;OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.&lt;/p&gt;
&lt;p&gt;Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large amount of memory,
which may lead to a Denial of Service.&lt;/p&gt;
&lt;p&gt;CWE: CWE-405: Asymmetric Resource Consumption (Amplification)&lt;/p&gt;
&lt;p&gt;Description: While a DTLS handshake is in progress, a peer may legitimately
have already moved on to the next epoch (for example, having sent its
ChangeCipherSpec and Finished messages) before the local endpoint has
processed the same transition, typically because of reordering on the
underlying UDP transport. OpenSSL buffers such early records so that they
can be processed once the local endpoint catches up.&lt;/p&gt;
&lt;p&gt;Buffering a record currently retains the entire read buffer it arrived in,
which is sized to hold the largest possible DTLS record (around 16
kilobytes), rather than just the bytes that make up the record itself. Up
to 100 such records may be buffered per connection. As a result, a peer
that sends a stream of small forged records claiming to belong to the next
epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of
memory, despite sending only a small fraction of that amount…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3819</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11623-1 — libopenssl-3-devel-3.5.3-8.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11623-1</link>
      <description>&lt;p&gt;libopenssl-3-devel-3.5.3-8.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-3-devel-3.5.3-8.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11623-1</guid>
    </item>
    <item>
      <title>RHSA-2026:59635 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:59635</link>
      <description>&lt;p&gt;openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption openssl: RPK server signature algorithm selection can dereference a missing certificate openssl: QUIC server may trigger double free when processing INITIAL packet openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler openssl: Double-free When Checking OCSP Stapled Response openssl: NULL pointer dereference in QUIC server initial packet handling openssl: NULL Dereference in Certificate Verification with OCSP Checking openssl: Possible NULL Dereference in Password-Based CMS Decryption openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate openssl: FFC-DH Peer Validation Uses Attacker-Supplied q openssl: Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() openssl: AES-OCB IV Ignored on EVP_Cipher() Path openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes openssl: Heap Use-After-Free in OpenSSL PKCS7_veri…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption openssl: RPK server signature algorithm selection can dereference a missing certificate openssl: QUIC server may trigger double free when processing INITIAL packet openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler openssl: Double-free When Checking OCSP Stapled Response openssl: NULL pointer dereference in QUIC server initial packet handling openssl: NULL Dereference in Certificate Verification with OCSP Checking openssl: Possible NULL Dereference in Password-Based CMS Decryption openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate openssl: FFC-DH Peer Validation Uses Attacker-Supplied q openssl: Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() openssl: AES-OCB IV Ignored on EVP_Cipher() Path openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes openssl: Heap Use-After-Free in OpenSSL PKCS7_veri…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:59635</guid>
    </item>
    <item>
      <title>RLSA-2026:67154 — Important: openssl security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67154</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)&lt;/p&gt;
&lt;p&gt;* openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)&lt;/p&gt;
&lt;p&gt;* openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)&lt;/p&gt;
&lt;p&gt;* openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)&lt;/p&gt;
&lt;p&gt;* openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)&lt;/p&gt;
&lt;p&gt;* openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)&lt;/p&gt;
&lt;p&gt;* openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)&lt;/p&gt;
&lt;p&gt;* openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)&lt;/p&gt;
&lt;p&gt;* openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [Rocky Linux 10.2.z] (JIRA:Rocky Linux-212362)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)&lt;/p&gt;
&lt;p&gt;* openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)&lt;/p&gt;
&lt;p&gt;* openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)&lt;/p&gt;
&lt;p&gt;* openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)&lt;/p&gt;
&lt;p&gt;* openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)&lt;/p&gt;
&lt;p&gt;* openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)&lt;/p&gt;
&lt;p&gt;* openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)&lt;/p&gt;
&lt;p&gt;* openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)&lt;/p&gt;
&lt;p&gt;* openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [Rocky Linux 10.2.z] (JIRA:Rocky Linux-212362)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67154</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23463-1 — Security update for openssl-3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23463-1</link>
      <description>&lt;p&gt;Security update for openssl-3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl-3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23463-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54874</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54874</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: openssl1.0, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl and 18 more&lt;/p&gt;
&lt;p&gt;Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service. CWE: CWE-405: Asymmetric Resource Consumption (Amplification) Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up. Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network. An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: openssl1.0, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl and 18 more&lt;/p&gt;
&lt;p&gt;Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service. CWE: CWE-405: Asymmetric Resource Consumption (Amplification) Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up. Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network. An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54874</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3005 — OpenSSL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3005</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3005</guid>
    </item>
  </channel>
</rss>
