Bug 2451094 (CVE-2026-31790)
| Summary: | CVE-2026-31790 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | cchiang, csutherl, dsoumis, jclere, pjindal, plodge, rhel-process-autobot, rmaucher, security-response-team, szappis, vchlup, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Deadline: | 2026-04-07 | ||
|
Description
OSIDB Bzimport
2026-03-25 03:14:17 UTC
This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2.2 Via RHSA-2026:12195 https://access.redhat.com/errata/RHSA-2026:12195 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19066 https://access.redhat.com/errata/RHSA-2026:19066 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19218 https://access.redhat.com/errata/RHSA-2026:19218 |