[Pkg-rust-maintainers] Bug#1142474: rust-openssl: CVE-2026-45784

Salvatore Bonaccorso carnil at debian.org
Mon Jul 20 13:20:38 BST 2026


Source: rust-openssl
Version: 0.10.79-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerability was published for rust-openssl.

CVE-2026-45784[0]:
| rust-openssl provides OpenSSL bindings for the Rust programming
| language. From 0.10.50 until 0.10.80,
| CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs
| incorrectly sized output buffers when used with AES
| key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a
| non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of
| the caller's buffer or Vec, producing attacker-controllable heap
| corruption when the plaintext length is attacker-influenced. This
| issue is fixed in version 0.10.80.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-45784
    https://www.cve.org/CVERecord?id=CVE-2026-45784
[1] https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq
[2] https://github.com/rust-openssl/rust-openssl/pull/2638
[3] https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7

Please adjust the affected versions in the BTS as needed.

REgards,
Salvatore



More information about the Pkg-rust-maintainers mailing list