{"id":"CVE-2026-31790","summary":"Incorrect Failure Handling in RSA KEM RSASVE Encapsulation","details":"Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.","modified":"2026-08-13T11:56:58.609087068Z","published":"2026-04-07T22:00:56.698Z","related":["ALSA-2026:19066","ALSA-2026:19218","ALSA-2026:39297","CGA-5hc5-p275-2wrf","SUSE-SU-2026:1213-1","SUSE-SU-2026:1214-1","SUSE-SU-2026:1215-1","SUSE-SU-2026:1216-1","SUSE-SU-2026:1256-1","SUSE-SU-2026:1257-1","SUSE-SU-2026:1291-1","SUSE-SU-2026:1375-1","SUSE-SU-2026:21037-1","SUSE-SU-2026:21065-1","SUSE-SU-2026:21107-1","SUSE-SU-2026:21186-1","openSUSE-SU-2026:10533-1","openSUSE-SU-2026:20525-1"],"database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-754"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31790.json"},"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31790.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31790"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260407.txt"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"89cd17a031e022211684eb7eb41190cf1910f9fa"},{"fixed":"5aada9c299a3b28fc82348f4e2b93805fa0a0e9c"},{"introduced":"4cb31128b5790819dfeea2739fbde265f71a10a2"},{"fixed":"204165c1550d3aa0f49395af654124cec2bbabf9"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"03b8620d6e9b7b4d5701865edb6ad86101fe5517"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"fixed":"286ddeaac037533bbdce65b3c689e3f7ffebf0f6"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"fixed":"fe686e15d84334b284f883118ed92f64b409b3aa"},{"fixed":"001e01db3e996e13ffc72386fe79d03a6683b5ac"},{"fixed":"abd8b2eec7e3f3fda60ecfb68498b246b52af482"},{"fixed":"b922e24e5b23ffb9cb9e14cadff23d91e9f7e406"},{"fixed":"d5f8e71cd0a54e961d0c3b174348f8308486f790"},{"fixed":"eed200f58cd8645ed77e46b7e9f764e284df379e"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.20"},{"introduced":"3.3.0"},{"fixed":"3.3.7"},{"introduced":"3.4.0"},{"fixed":"3.4.5"},{"introduced":"3.5.0"},{"fixed":"3.5.6"},{"introduced":"3.6.0"},{"fixed":"3.6.2"}]}}],"versions":["openssl-3.0.19","openssl-3.3.6","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.0-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.3-POST-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.0-PRE-CLANG-FORMAT-WEBKIT","3.3-PRE-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.0.18","openssl-3.3.5","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.0.17","openssl-3.3.4","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.0.16","openssl-3.3.3","openssl-3.4.1","openssl-3.4.0","openssl-3.0.15","openssl-3.3.2","openssl-3.0.14","openssl-3.3.1","openssl-3.3.0","openssl-3.0.13","openssl-3.0.12","openssl-3.0.11","openssl-3.0.10","openssl-3.0.9","openssl-3.0.8","openssl-3.0.7","openssl-3.0.6","openssl-3.0.5","openssl-3.0.4","openssl-3.0.3","openssl-3.0.2","openssl-3.0.1","openssl-3.0.0"],"database_specific":{"vanir_signatures":[{"target":{"file":"providers/implementations/kem/rsa_kem.c","function":"rsasve_generate"},"deprecated":false,"digest":{"function_hash":"189542578001022051844638676180069418852","length":815},"id":"CVE-2026-31790-018ce97e","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790"},{"target":{"file":"providers/implementations/kem/rsa_kem.c"},"deprecated":false,"digest":{"line_hashes":["278196644910020378797877326289562716464","128347082521489651704136040653285145470","52209736684511955497537762942657051729","142213326511995995366934168172526029934","3123676691629820969540701266136695106","87606255750554511681517734874131183189","145012507772233658079047458768781416199","303537148589549380972349267515809788322","189943355530216116721748686226778704218","162922700271686436107402731224121909713","338343483140302614182963625022660953531","174900505482554411594506357522639767296","289381205478540363242016959369444210059","212692919502018645166428121117180913811"],"threshold":0.9},"id":"CVE-2026-31790-59f13f0b","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e"},{"id":"CVE-2026-31790-8c11327b","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac","target":{"file":"providers/implementations/kem/rsa_kem.c"},"deprecated":false,"digest":{"line_hashes":["278196644910020378797877326289562716464","128347082521489651704136040653285145470","52209736684511955497537762942657051729","142213326511995995366934168172526029934","3123676691629820969540701266136695106","87606255750554511681517734874131183189","145012507772233658079047458768781416199","303537148589549380972349267515809788322","189943355530216116721748686226778704218","162922700271686436107402731224121909713","338343483140302614182963625022660953531","174900505482554411594506357522639767296","289381205478540363242016959369444210059","212692919502018645166428121117180913811"],"threshold":0.9}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790","target":{"file":"providers/implementations/kem/rsa_kem.c"},"deprecated":false,"digest":{"line_hashes":["278196644910020378797877326289562716464","128347082521489651704136040653285145470","52209736684511955497537762942657051729","142213326511995995366934168172526029934","3123676691629820969540701266136695106","87606255750554511681517734874131183189","145012507772233658079047458768781416199","303537148589549380972349267515809788322","189943355530216116721748686226778704218","162922700271686436107402731224121909713","338343483140302614182963625022660953531","174900505482554411594506357522639767296","289381205478540363242016959369444210059","212692919502018645166428121117180913811"],"threshold":0.9},"id":"CVE-2026-31790-9104c8e6"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e","target":{"file":"providers/implementations/kem/rsa_kem.c","function":"rsasve_generate"},"deprecated":false,"digest":{"function_hash":"189542578001022051844638676180069418852","length":815},"id":"CVE-2026-31790-b7501cc3"},{"target":{"file":"providers/implementations/kem/rsa_kem.c","function":"rsasve_generate"},"deprecated":false,"digest":{"function_hash":"189542578001022051844638676180069418852","length":815},"id":"CVE-2026-31790-ba26f35f","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406"},{"id":"CVE-2026-31790-bce81a11","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac","target":{"file":"providers/implementations/kem/rsa_kem.c","function":"rsasve_generate"},"deprecated":false,"digest":{"function_hash":"189542578001022051844638676180069418852","length":815}},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406","target":{"file":"providers/implementations/kem/rsa_kem.c"},"deprecated":false,"digest":{"line_hashes":["278196644910020378797877326289562716464","128347082521489651704136040653285145470","52209736684511955497537762942657051729","142213326511995995366934168172526029934","3123676691629820969540701266136695106","87606255750554511681517734874131183189","145012507772233658079047458768781416199","303537148589549380972349267515809788322","189943355530216116721748686226778704218","162922700271686436107402731224121909713","338343483140302614182963625022660953531","174900505482554411594506357522639767296","289381205478540363242016959369444210059","212692919502018645166428121117180913811"],"threshold":0.9},"id":"CVE-2026-31790-e2fd0c60","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31790.json","vanir_signatures_modified":"2026-08-12T15:32:18Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}