Multiple OpenSSL Flaws Expose Sensitive Data in RSA KEM Handling
ID: c85bfc3a-f46c-516b-ada9-975568b55c54
STIX ID: report--c85bfc3a-f46c-516b-ada9-975568b55c54
Feed Name: GBHackers
A newly disclosed moderate-severity OpenSSL vulnerability (CVE-2026-31790) in RSASVE encapsulation can cause RSA_public_encrypt errors to be misinterpreted as success, leading applications to return uninitialized ciphertext buffer contents and potentially leak sensitive memory. OpenSSL 3.x releases are affected; vendors have issued patches (specific 3.x versions listed) and recommend validating public keys with EVP_PKEY_public_check()/EVP_PKEY_public_check_quick() or upgrading to the provided patched releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
