CVE-2026-45784

NameCVE-2026-45784
Descriptionrust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142474

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-openssl (PTS)bullseye0.10.29-1fixed
bullseye (security)0.10.29-1+deb11u1fixed
bookworm0.10.45-1fixed
trixie0.10.72-1vulnerable
forky, sid0.10.79-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-opensslsourcebullseye(not affected)
rust-opensslsourcebookworm(not affected)
rust-opensslsource(unstable)(unfixed)1142474

Notes

[bookworm] - rust-openssl <not-affected> (Vulnerable CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are absent too)
[bullseye] - rust-openssl <not-affected> (Vulnerable CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are absent too)
https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq
https://github.com/rust-openssl/rust-openssl/pull/2638
Fixed by: https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7 (openssl-v0.10.80)

Search for package or bug name: Reporting problems