{"id":"USN-8414-2","summary":"openssl, openssl1.0 vulnerabilities","details":"USN-8414-1 fixed several vulnerabilities in OpenSSL. This update provides\nthe corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu\n18.04 LTS, and Ubuntu 20.04 LTS.\n\n Original advisory details:\n\nFrank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1\ncontent parsing. An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or obtain sensitive\ninformation. (CVE-2026-34180)\n\nAsim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could\naccept forged CMS AuthEnvelopedData messages. An attacker could possibly\nuse this issue to bypass message authentication checks. (CVE-2026-34182)\n\nMayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan\nZhang discovered that OpenSSL had a possible NULL dereference in password-\nbased CMS decryption. An attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-42766)\n\nZhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a\nNULL pointer dereference in CRMF EncryptedValue decryption. An attacker\ncould possibly use this issue to cause OpenSSL to crash, resulting in a\ndenial of service. (CVE-2026-42767)\n\nThai Duong discovered that OpenSSL had a heap use-after-free in\nPKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-45447)\n\nZehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer\noverflow in ASN.1 multibyte string conversion. An attacker could possibly\nuse this issue to cause OpenSSL to crash, resulting in a denial of service,\nor execute arbitrary code. (CVE-2026-7383)\n\nBhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS\npassword-based decryption. An attacker could possibly use this issue to\ncause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076)","modified":"2026-06-11T10:45:32.001549477Z","published":"2026-06-09T18:29:37Z","related":["UBUNTU-CVE-2026-34180","UBUNTU-CVE-2026-34182","UBUNTU-CVE-2026-42766","UBUNTU-CVE-2026-45447","UBUNTU-CVE-2026-7383","UBUNTU-CVE-2026-9076"],"upstream":["UBUNTU-CVE-2026-7383","UBUNTU-CVE-2026-9076","UBUNTU-CVE-2026-34180","UBUNTU-CVE-2026-34182","UBUNTU-CVE-2026-42766","UBUNTU-CVE-2026-45447"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8414-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-7383"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-9076"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34180"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-34182"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42766"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-45447"}],"affected":[{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1f-1ubuntu2.27+esm14"}]}],"versions":["1.0.1e-3ubuntu1","1.0.1e-4ubuntu1","1.0.1e-4ubuntu2","1.0.1e-4ubuntu3","1.0.1e-4ubuntu4","1.0.1f-1ubuntu1","1.0.1f-1ubuntu2","1.0.1f-1ubuntu2.1","1.0.1f-1ubuntu2.2","1.0.1f-1ubuntu2.3","1.0.1f-1ubuntu2.4","1.0.1f-1ubuntu2.5","1.0.1f-1ubuntu2.7","1.0.1f-1ubuntu2.8","1.0.1f-1ubuntu2.11","1.0.1f-1ubuntu2.12","1.0.1f-1ubuntu2.15","1.0.1f-1ubuntu2.16","1.0.1f-1ubuntu2.17","1.0.1f-1ubuntu2.18","1.0.1f-1ubuntu2.19","1.0.1f-1ubuntu2.20","1.0.1f-1ubuntu2.21","1.0.1f-1ubuntu2.22","1.0.1f-1ubuntu2.23","1.0.1f-1ubuntu2.24","1.0.1f-1ubuntu2.25","1.0.1f-1ubuntu2.26","1.0.1f-1ubuntu2.27","1.0.1f-1ubuntu2.27+esm1","1.0.1f-1ubuntu2.27+esm2","1.0.1f-1ubuntu2.27+esm3","1.0.1f-1ubuntu2.27+esm4","1.0.1f-1ubuntu2.27+esm5","1.0.1f-1ubuntu2.27+esm6","1.0.1f-1ubuntu2.27+esm7","1.0.1f-1ubuntu2.27+esm9","1.0.1f-1ubuntu2.27+esm10","1.0.1f-1ubuntu2.27+esm11","1.0.1f-1ubuntu2.27+esm12","1.0.1f-1ubuntu2.27+esm13"],"ecosystem_specific":{"binaries":[{"binary_version":"1.0.1f-1ubuntu2.27+esm14","binary_name":"libssl1.0.0"},{"binary_version":"1.0.1f-1ubuntu2.27+esm14","binary_name":"openssl"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:14.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-7383"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-9076"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-34180"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-42766"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}],"id":"CVE-2026-45447"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8414-2.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.2g-1ubuntu4.20+esm16"}]}],"versions":["1.0.2d-0ubuntu1","1.0.2d-0ubuntu2","1.0.2e-1ubuntu1","1.0.2f-2ubuntu1","1.0.2g-1ubuntu2","1.0.2g-1ubuntu3","1.0.2g-1ubuntu4","1.0.2g-1ubuntu4.1","1.0.2g-1ubuntu4.2","1.0.2g-1ubuntu4.4","1.0.2g-1ubuntu4.5","1.0.2g-1ubuntu4.6","1.0.2g-1ubuntu4.8","1.0.2g-1ubuntu4.9","1.0.2g-1ubuntu4.10","1.0.2g-1ubuntu4.11","1.0.2g-1ubuntu4.12","1.0.2g-1ubuntu4.13","1.0.2g-1ubuntu4.14","1.0.2g-1ubuntu4.15","1.0.2g-1ubuntu4.16","1.0.2g-1ubuntu4.17","1.0.2g-1ubuntu4.18","1.0.2g-1ubuntu4.19","1.0.2g-1ubuntu4.20","1.0.2g-1ubuntu4.20+esm1","1.0.2g-1ubuntu4.20+esm2","1.0.2g-1ubuntu4.20+esm3","1.0.2g-1ubuntu4.20+esm4","1.0.2g-1ubuntu4.20+esm5","1.0.2g-1ubuntu4.20+esm6","1.0.2g-1ubuntu4.20+esm7","1.0.2g-1ubuntu4.20+esm9","1.0.2g-1ubuntu4.20+esm10","1.0.2g-1ubuntu4.20+esm11","1.0.2g-1ubuntu4.20+esm12","1.0.2g-1ubuntu4.20+esm13","1.0.2g-1ubuntu4.20+esm14","1.0.2g-1ubuntu4.20+esm15"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_version":"1.0.2g-1ubuntu4.20+esm16","binary_name":"libssl1.0.0"},{"binary_version":"1.0.2g-1ubuntu4.20+esm16","binary_name":"openssl"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-7383"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-9076"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-34180"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-42766"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}],"id":"CVE-2026-45447"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8414-2.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.1~18.04.23+esm9"}]}],"versions":["1.0.2g-1ubuntu13","1.0.2g-1ubuntu14","1.0.2n-1ubuntu1","1.1.0g-2ubuntu1","1.1.0g-2ubuntu2","1.1.0g-2ubuntu3","1.1.0g-2ubuntu4","1.1.0g-2ubuntu4.1","1.1.0g-2ubuntu4.3","1.1.1-1ubuntu2.1~18.04.1","1.1.1-1ubuntu2.1~18.04.2","1.1.1-1ubuntu2.1~18.04.3","1.1.1-1ubuntu2.1~18.04.4","1.1.1-1ubuntu2.1~18.04.5","1.1.1-1ubuntu2.1~18.04.6","1.1.1-1ubuntu2.1~18.04.7","1.1.1-1ubuntu2.1~18.04.8","1.1.1-1ubuntu2.1~18.04.9","1.1.1-1ubuntu2.1~18.04.10","1.1.1-1ubuntu2.1~18.04.13","1.1.1-1ubuntu2.1~18.04.14","1.1.1-1ubuntu2.1~18.04.15","1.1.1-1ubuntu2.1~18.04.17","1.1.1-1ubuntu2.1~18.04.19","1.1.1-1ubuntu2.1~18.04.20","1.1.1-1ubuntu2.1~18.04.21","1.1.1-1ubuntu2.1~18.04.22","1.1.1-1ubuntu2.1~18.04.23","1.1.1-1ubuntu2.1~18.04.23+esm1","1.1.1-1ubuntu2.1~18.04.23+esm3","1.1.1-1ubuntu2.1~18.04.23+esm4","1.1.1-1ubuntu2.1~18.04.23+esm5","1.1.1-1ubuntu2.1~18.04.23+esm6","1.1.1-1ubuntu2.1~18.04.23+esm7","1.1.1-1ubuntu2.1~18.04.23+esm8"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.1-1ubuntu2.1~18.04.23+esm9","binary_name":"libssl1.1"},{"binary_version":"1.1.1-1ubuntu2.1~18.04.23+esm9","binary_name":"openssl"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-7383"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-9076"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-34180"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-42766"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"high","type":"Ubuntu"}],"id":"CVE-2026-45447"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8414-2.json"}},{"package":{"name":"openssl1.0","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/openssl1.0?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.2n-1ubuntu5.13+esm5"}]}],"versions":["1.0.2n-1ubuntu2","1.0.2n-1ubuntu3","1.0.2n-1ubuntu4","1.0.2n-1ubuntu5","1.0.2n-1ubuntu5.1","1.0.2n-1ubuntu5.2","1.0.2n-1ubuntu5.3","1.0.2n-1ubuntu5.4","1.0.2n-1ubuntu5.5","1.0.2n-1ubuntu5.6","1.0.2n-1ubuntu5.7","1.0.2n-1ubuntu5.8","1.0.2n-1ubuntu5.9","1.0.2n-1ubuntu5.10","1.0.2n-1ubuntu5.11","1.0.2n-1ubuntu5.12","1.0.2n-1ubuntu5.13","1.0.2n-1ubuntu5.13+esm1","1.0.2n-1ubuntu5.13+esm2","1.0.2n-1ubuntu5.13+esm3","1.0.2n-1ubuntu5.13+esm4"],"ecosystem_specific":{"binaries":[{"binary_version":"1.0.2n-1ubuntu5.13+esm5","binary_name":"libssl1.0.0"},{"binary_version":"1.0.2n-1ubuntu5.13+esm5","binary_name":"openssl1.0"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-7383"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-9076"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-34180"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-42766"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}],"id":"CVE-2026-45447"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8414-2.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1f-1ubuntu2.24+esm4"}]}],"versions":["1.1.1c-1ubuntu4","1.1.1d-2ubuntu3","1.1.1d-2ubuntu6","1.1.1f-1ubuntu1","1.1.1f-1ubuntu2","1.1.1f-1ubuntu2.1","1.1.1f-1ubuntu2.2","1.1.1f-1ubuntu2.3","1.1.1f-1ubuntu2.4","1.1.1f-1ubuntu2.5","1.1.1f-1ubuntu2.8","1.1.1f-1ubuntu2.9","1.1.1f-1ubuntu2.10","1.1.1f-1ubuntu2.11","1.1.1f-1ubuntu2.12","1.1.1f-1ubuntu2.13","1.1.1f-1ubuntu2.15","1.1.1f-1ubuntu2.16","1.1.1f-1ubuntu2.17","1.1.1f-1ubuntu2.18","1.1.1f-1ubuntu2.19","1.1.1f-1ubuntu2.20","1.1.1f-1ubuntu2.21","1.1.1f-1ubuntu2.22","1.1.1f-1ubuntu2.23","1.1.1f-1ubuntu2.24","1.1.1f-1ubuntu2.24+esm1","1.1.1f-1ubuntu2.24+esm2","1.1.1f-1ubuntu2.24+esm3"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.1f-1ubuntu2.24+esm4","binary_name":"libssl1.1"},{"binary_version":"1.1.1f-1ubuntu2.24+esm4","binary_name":"openssl"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-7383"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-9076"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-34180"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-42766"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}],"id":"CVE-2026-45447"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8414-2.json"}}],"schema_version":"1.7.5"}