Search CVE reports


Toggle filters

1 – 10 of 13 results


CVE-2026-44662

Medium priority
Needs evaluation

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42327

Medium priority
Needs evaluation

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target =...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41898

Medium priority
Needs evaluation

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41681

Medium priority
Vulnerable

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Vulnerable Vulnerable Not affected Not affected
Show less packages

CVE-2026-41678

Medium priority
Vulnerable

rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Vulnerable Vulnerable Vulnerable Not affected
Show less packages

CVE-2026-41677

Medium priority
Vulnerable

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2026-41676

Medium priority
Vulnerable

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2023-53159

Medium priority
Fixed

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Not affected Not affected Fixed Fixed
Show less packages

CVE-2025-3416

Medium priority

Some fixes available 1 of 3

A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to...

1 affected package

rust-openssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Not affected Fixed Not affected Not affected
Show less packages

CVE-2025-24898

Medium priority

Some fixes available 3 of 5

rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice pointing into the `server` argument's buffer but with a lifetime bound to the `client`...

2 affected packages

rust-openssl, rust-openssl-sys

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Not affected Fixed Fixed Fixed
rust-openssl-sys Not affected Not affected Not affected Not affected
Show less packages