logo

OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed

ID: 961e4707-a8bb-5447-ac41-4211d1c291d8

STIX ID: report--961e4707-a8bb-5447-ac41-4211d1c291d8

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

OpenSSL released an advisory describing seven vulnerabilities — most notably a Moderate-severity RSA KEM memory leak (CVE-2026-31790) where failed RSA encapsulation can expose uninitialized memory, plus several Low-severity flaws (AES-CFB-128 OOB read, DANE client use-after-free, NULL pointer dereferences, and a 32-bit heap buffer overflow). Affected OpenSSL 3.0–3.6 users are advised to upgrade to specified patched versions (e.g., 3.6.2, 3.5.6, 3.4.5) or apply a mitigation (call EVP_PKEY_public_check/_quick before EVP_PKEY_encapsulate) until updates can be deployed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.