CVE-2026-75803

Sin clasificar

Vulnerabilidad sin clasificar en OpenSSL. Publicada el 25 de agosto de 2026. Afecta a Debian 12 y Ubuntu 24.04. Corregida en Debian 13 (3.5.7-1~deb13u2), Ubuntu 22.04 (3.0.2-0ubuntu1.29), Ubuntu 24.04 (3.0.13-0ubuntu3.15), Ubuntu 26.04 (3.5.5-1ubuntu3.5) y Ubuntu FIPS-updates 24.04 (3.0.13-0ubuntu3.15+Fips1). Sin parche todavía para Debian 12.

Descripción

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and ex

Descripción original en inglés: todavía no se ha traducido.

Versiones que la corrigen

Distribución Versión del paquete
Debian 13 3.5.7-1~deb13u2
Ubuntu 22.04 3.0.2-0ubuntu1.29
Ubuntu 24.04 3.0.13-0ubuntu3.15
Ubuntu 26.04 3.5.5-1ubuntu3.5
Ubuntu FIPS-updates 24.04 3.0.13-0ubuntu3.15+Fips1

Avisos oficiales

Datos de OSV.dev, publicados bajo licencia CC BY 4.0. La severidad es la puntuación base CVSS 3.1 calculada a partir del vector publicado. Esta ficha se genera automáticamente y no sustituye al aviso oficial de tu distribución; así se elabora la lista.