Intel

AIKIDO-2026-142108

openssl is vulnerable to Out-of-bounds Write

Out-of-bounds WriteCVE-2026-63072 Published 6 days ago

55

Medium Risk

This Affects:

C++openssl
1.1.1 - 3.0.21
Fixed in 3.0.22
3.4.0 - 3.4.6
Fixed in 3.4.7
3.5.0 - 3.5.7
Fixed in 3.5.8
3.6.0 - 3.6.3
Fixed in 3.6.4
4.0.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

CMS decryption sizes the key unwrap output buffer from the reported unwrapped key length, but padded AES key unwrap can write and clear 8 bytes past that length. A CMS message whose key wrap algorithm identifier selects the padded variant reaches this write from CMS_decrypt(), and the integrity check then fails, which corrupts the heap and typically crashes the process. The fix sizes the output buffer for the largest write the unwrap can perform.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application decrypts untrusted CMS messages.

Background info

openssl is vulnerable to Out-of-bounds Write in versions 1.1.1 - 3.0.21, 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.

How to fix this

Upgrade the openssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform