This bug was fixed in the package openssl - 3.0.13-0ubuntu3.15

---------------
openssl (3.0.13-0ubuntu3.15) noble-security; urgency=medium

  * SECURITY UPDATE: Excessive Memory Use Buffering DTLS Records for a Future
    Epoch
    - debian/patches/CVE-2026-54874-1.patch: Avoid full read buffer allocation
      when buffering DTLS records in ssl/record/rec_layer_d1.c,
      ssl/record/record.h, ssl/record/ssl3_record.c.
    - debian/patches/CVE-2026-54874-2.patch: ssl/record: lower the DTLS
      unprocessed_rcds queue limit in ssl/record/rec_layer_d1.c,
      ssl/record/record_local.h, ssl/record/ssl3_record.c.
    - CVE-2026-54874
  * SECURITY UPDATE: Heap Buffer Overflow in CMS Key Unwrapping
    - debian/patches/CVE-2026-63072-1.patch: Add test for CVE-2026-63072 in
      test/cmsapitest.c, test/recipes/80-test_cmsapi.t.
    - debian/patches/CVE-2026-63072-2.patch: Fix heap buffer overflow (8-byte
      OOB write) in AES-WRAP-PAD unwrap in crypto/cms/cms_kari.c.
    - CVE-2026-63072
  * SECURITY UPDATE: CMP Indefinite Cache Growth of ExtraCerts
    - debian/patches/CVE-2026-63074-1.patch: Add a test for restricting growth
      in cmp cert cache in test/build.info, test/cmp_extracerts_dos_test.c,
      test/recipes/65-test_cmp_msg.t.
    - debian/patches/CVE-2026-63074-2.patch: Fix unbounded cert cache growth in
      cmp in crypto/cmp/cmp_vfy.c.
    - CVE-2026-63074
  * SECURITY UPDATE: Invalid Pointer Dereference in CMP Server via Crafted
    protectionAlg
    - debian/patches/CVE-2026-63076-1.patch: Add test for CVE-2026-63076 in
      test/cmp_protect_test.c.
    - debian/patches/CVE-2026-63076-2.patch: Fix Remote NULL deref in
      ossl_cmp_calc_protection() via crafted protectionAlg in
      crypto/cmp/cmp_protect.c.
    - CVE-2026-63076
  * SECURITY UPDATE: AEAD Forgeries with Empty Ciphertext When Using
    EVP_Cipher()
    - debian/patches/CVE-2026-75803-1.patch: Check the tag on EVP_Cipher()
      finalize: Poly1305 and OCB AEADs in
      providers/implementations/ciphers/cipher_aes_ocb.c,
      providers/implementations/ciphers/cipher_chacha20_poly1305.c.
    - debian/patches/CVE-2026-75803-2.patch: Add tests for empty AEAD
      EVP_Cipher() finalization in test/evp_extra_test.c.
    - CVE-2026-75803

 -- Marc Deslauriers <[email protected]>  Tue, 18 Aug 2026
08:10:36 -0400

** Changed in: openssl (Ubuntu Noble)
       Status: Fix Committed => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54874

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63072

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63074

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63076

** CVE added: https://cve.org/CVERecord?id=CVE-2026-75803

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2137464

Title:
  crypto/ec/asm/ecp_nistp521-ppc64.pl output regex failure

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2137464/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to