Search CVE reports
11 – 20 of 146 results
Some fixes available 1 of 4
Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not affected | Not affected | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Vulnerable | Not affected | Not affected |
| edk2 | Vulnerable | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Vulnerable | Not in release | Not in release | — | — |
Some fixes available 8 of 18
Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Fixed | Fixed |
| openssl-fips | Not in release | Not in release | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Fixed |
| nodejs | Not affected | Not affected | Vulnerable | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 1 of 4
Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not affected | Not affected | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Vulnerable | Not affected | Not affected |
| edk2 | Vulnerable | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Vulnerable | Not in release | Not in release | — | — |
Some fixes available 8 of 18
Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Fixed | Fixed |
| openssl-fips | Not in release | Not in release | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Fixed |
| nodejs | Not affected | Not affected | Vulnerable | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 4 of 9
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Not affected | Not affected |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Vulnerable | Vulnerable | Not affected | Not affected | Not affected |
| edk2-hwe | Vulnerable | Not in release | Not in release | — | — |
Some fixes available 4 of 9
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Not affected | Not affected |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Vulnerable | Vulnerable | Not affected | Not affected | Not affected |
| edk2-hwe | Vulnerable | Not in release | Not in release | — | — |
Some fixes available 1 of 5
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not affected | Not affected | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 4 of 9
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Not affected | Not affected |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Needs evaluation | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 1 of 5
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Not affected | Not affected | Not affected | Not affected |
| openssl-fips | Not in release | Not affected | Not affected | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Not affected |
| nodejs | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
| edk2 | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
| edk2-hwe | Needs evaluation | Not in release | Not in release | — | — |
Some fixes available 9 of 18
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| openssl | Fixed | Fixed | Fixed | Fixed | Fixed |
| openssl-fips | Not in release | Fixed | Not in release | — | — |
| openssl1.0 | Not in release | Not in release | Not in release | — | Fixed |
| nodejs | Not affected | Not affected | Vulnerable | Not affected | Needs evaluation |
| edk2 | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| edk2-hwe | Vulnerable | Not in release | Not in release | — | — |