{"id":"CVE-2026-63072","summary":"Heap Buffer Overflow in CMS Key Unwrapping","details":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.","modified":"2026-08-30T08:17:27.444644Z","published":"2026-08-25T12:59:34.428Z","related":["openSUSE-SU-2026:11623-1"],"database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63072.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63072.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260825.txt"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"11b7b6ea3b65a584e1d31408ed1bdb139465cffd"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"introduced":"89cd17a031e022211684eb7eb41190cf1910f9fa"},{"introduced":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"fixed":"f089acdf4bc7ba94a79f4bf6eb7362c3e7d14aa9"},{"fixed":"d3c1b1169b3569ff3069e5b399f47b2b28e03d79"},{"fixed":"f4dc4d58b48d346a8270183f89acf826d459b0ca"},{"fixed":"0c5d912057abf47505b4ad455da49fbab99b76f1"},{"fixed":"a279090b9cd6b682a5a178410765a63e619fa2d9"},{"fixed":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"fixed":"2a3dac874c8057c1f0186849bf1ede1ae7b6b756"},{"fixed":"87784ad619af36b8807c2044b3940006fccc1e42"},{"fixed":"9530a5fd1aacaeccdced4478ea2340a480613335"},{"fixed":"9ec2f6d2ae2bcad907cf7ee38584855bafe4979a"},{"fixed":"a0c8ec557d9cac078f032d76cdf684fe743eb382"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.2"},{"introduced":"3.6.0"},{"fixed":"3.6.4"},{"introduced":"3.5.0"},{"fixed":"3.5.8"},{"introduced":"3.4.0"},{"fixed":"3.4.7"},{"introduced":"3.0.0"},{"fixed":"3.0.22"},{"introduced":"1.1.1"},{"fixed":"1.1.1zi"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["openssl-3.0.21","openssl-3.4.6","openssl-3.5.7","openssl-3.6.3","openssl-4.0.1","openssl-4.0.0","openssl-3.0.20","openssl-3.4.5","openssl-3.5.6","openssl-3.6.2","openssl-3.0.19","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.0-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.0-PRE-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.0.18","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.0.17","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.0.16","openssl-3.4.1","openssl-3.4.0","openssl-3.0.15","openssl-3.0.14","openssl-3.0.13","openssl-3.0.12","openssl-3.0.11","openssl-3.0.10","openssl-3.0.9","openssl-3.0.8","openssl-3.0.7","openssl-3.0.6","openssl-3.0.5","openssl-3.0.4","openssl-3.0.3","openssl-3.0.2","openssl-3.0.1","openssl-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63072.json","vanir_signatures_modified":"2026-08-30T08:17:27Z","vanir_signatures":[{"target":{"file":"crypto/cms/cms_kari.c"},"deprecated":false,"digest":{"line_hashes":["208136681009025530992181983177450609462","67492296196001728152399820960887368767","88888296945704491112425341945148345197","77490842245204716087942480681456086748","167791123496514995312111627585598185110","58809577220617132767517088028514660857","207631790121528015800023699476018421649","256562552210483298504173461767217798440"],"threshold":0.9},"id":"CVE-2026-63072-055aceb1","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42"},{"id":"CVE-2026-63072-08cbc8d9","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","target":{"file":"crypto/cms/cms_kari.c"},"deprecated":false,"digest":{"line_hashes":["208136681009025530992181983177450609462","67492296196001728152399820960887368767","86119493663496307471447645762303651773","103971948677565821055656542659370118987","34529704455751087727912697608663393448","19398002998227456220659388596547811","207631790121528015800023699476018421649","256562552210483298504173461767217798440"],"threshold":0.9}},{"id":"CVE-2026-63072-2eb41dcb","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","target":{"file":"crypto/cms/cms_kemri.c"},"deprecated":false,"digest":{"line_hashes":["190181369754425626514088426314121489343","302983512749972924364577970277620573998","300247287928641771380098240730580468045","26618932074692139943363891828533656326","137036785119351147396437308987354428173","284265881093827514920610416597873339521","207631790121528015800023699476018421649","72083095091851580583601949470712484947"],"threshold":0.9}},{"id":"CVE-2026-63072-37741858","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","target":{"file":"crypto/cms/cms_kemri.c","function":"cms_kek_cipher"},"deprecated":false,"digest":{"function_hash":"316413486422965383581191612484836649227","length":1055}},{"deprecated":false,"digest":{"function_hash":"316413486422965383581191612484836649227","length":1055},"id":"CVE-2026-63072-48232a5e","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","target":{"file":"crypto/cms/cms_kemri.c","function":"cms_kek_cipher"}},{"digest":{"function_hash":"209945243013429542813762455339476825228","length":951},"id":"CVE-2026-63072-563f42ed","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","target":{"file":"crypto/cms/cms_kari.c","function":"cms_kek_cipher"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["208136681009025530992181983177450609462","67492296196001728152399820960887368767","86119493663496307471447645762303651773","103971948677565821055656542659370118987","34529704455751087727912697608663393448","19398002998227456220659388596547811","207631790121528015800023699476018421649","256562552210483298504173461767217798440"],"threshold":0.9},"id":"CVE-2026-63072-7dad758a","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","target":{"file":"crypto/cms/cms_kari.c"}},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","target":{"file":"crypto/cms/cms_kari.c"},"deprecated":false,"digest":{"line_hashes":["208136681009025530992181983177450609462","67492296196001728152399820960887368767","88888296945704491112425341945148345197","77490842245204716087942480681456086748","167791123496514995312111627585598185110","58809577220617132767517088028514660857","207631790121528015800023699476018421649","256562552210483298504173461767217798440"],"threshold":0.9},"id":"CVE-2026-63072-8b81eab8","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["190181369754425626514088426314121489343","302983512749972924364577970277620573998","300247287928641771380098240730580468045","26618932074692139943363891828533656326","137036785119351147396437308987354428173","284265881093827514920610416597873339521","207631790121528015800023699476018421649","72083095091851580583601949470712484947"],"threshold":0.9},"id":"CVE-2026-63072-947c82fa","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","target":{"file":"crypto/cms/cms_kemri.c"}},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","target":{"file":"crypto/cms/cms_kari.c","function":"cms_kek_cipher"},"deprecated":false,"digest":{"function_hash":"209945243013429542813762455339476825228","length":951},"id":"CVE-2026-63072-9fd87151","signature_type":"Function"},{"target":{"file":"crypto/cms/cms_kari.c","function":"cms_kek_cipher"},"deprecated":false,"digest":{"function_hash":"209945243013429542813762455339476825228","length":951},"id":"CVE-2026-63072-a9f7e2b1","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a"},{"digest":{"line_hashes":["208136681009025530992181983177450609462","67492296196001728152399820960887368767","88888296945704491112425341945148345197","77490842245204716087942480681456086748","167791123496514995312111627585598185110","58809577220617132767517088028514660857","207631790121528015800023699476018421649","256562552210483298504173461767217798440"],"threshold":0.9},"id":"CVE-2026-63072-c1235256","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","target":{"file":"crypto/cms/cms_kari.c"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["28170854778703993674264004058177114599","73132526844288570625317440636111911761","177405411499435185068645597737938634778","224809958623850711330610094965797758930","295554444428855106393106961197201359586"],"threshold":0.9},"id":"CVE-2026-63072-c377fa22","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e04bd3433fd84e1861bf258ea37928d9845e6a86","target":{"file":"include/openssl/opensslv.h"}},{"id":"CVE-2026-63072-dd096520","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","target":{"file":"crypto/cms/cms_kari.c","function":"cms_kek_cipher"},"deprecated":false,"digest":{"function_hash":"115190944145237027672058340203765188425","length":980}},{"source":"https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","target":{"file":"crypto/cms/cms_kari.c","function":"cms_kek_cipher"},"deprecated":false,"digest":{"length":980,"function_hash":"115190944145237027672058340203765188425"},"id":"CVE-2026-63072-fd4e40aa","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}