问题摘要: OpenSSL 的 CMS 解密功能在分配密钥解包输出缓冲区时,依据查询到的解包密钥大小来确定缓冲区大小。然而,AES-WRAP-PAD 解包原语可能会写入并清除比查询结果多出 8 字节的内存,从而导致一次 8 字节的堆溢出写入(out-of-bounds heap write)。 影响摘要: 攻击者通过提供精心构造的 CMS 消息,可在受害者使用 函数解密时触发确定性的 8 字节堆溢出写入,进而破坏堆内存结构,通常导致服务拒绝(Denial of Service, DoS)。 CWE 编号: CWE-
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75803 | AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() | |
| CVE-2026-18798 | QUIC Server May Trigger Double Free When Processing INITIAL Packet | |
| CVE-2026-54874 | Excessive Memory Use Buffering DTLS Records for a Future Epoch | |
| CVE-2026-63074 | CMP Indefinite Cache Growth of ExtraCerts | |
| CVE-2026-63073 | Untrusted Sender DN Used as Format String in CMP Response Validation | |
| CVE-2026-63075 | QUIC ACK-only Packet Retention Can Cause Memory Exhaustion | |
| CVE-2026-63076 | Invalid Pointer Dereference in CMP Server via Crafted protectionAlg | |
| CVE-2026-14457 | RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate |
No comments yet