Bug 2451094 (CVE-2026-31790)
| Summary: | CVE-2026-31790 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | akhatavk, aos-team-art-private, asdas, cchiang, csutherl, dpaolell, dsoumis, jclere, jdelft, jupierce, jwon, lgarciaa, mbiarnes, pjindal, plodge, ppalepu, ppostler, prdhamdh, rhel-process-autobot, rmaucher, security-response-team, sghai, sidsharm, suppawar, szappis, vchlup, vlaad, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Deadline: | 2026-04-07 | ||
|
Description
OSIDB Bzimport
2026-03-25 03:14:17 UTC
This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2.2 Via RHSA-2026:12195 https://access.redhat.com/errata/RHSA-2026:12195 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19066 https://access.redhat.com/errata/RHSA-2026:19066 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19218 https://access.redhat.com/errata/RHSA-2026:19218 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:27745 https://access.redhat.com/errata/RHSA-2026:27745 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27746 https://access.redhat.com/errata/RHSA-2026:27746 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:27744 https://access.redhat.com/errata/RHSA-2026:27744 This issue has been addressed in the following products: Red Hat JBoss Core Services 2.4.62.SP4 Via RHSA-2026:27201 https://access.redhat.com/errata/RHSA-2026:27201 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Red Hat Enterprise Linux 9.6 Extended Update Support Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:28832 https://access.redhat.com/errata/RHSA-2026:28832 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:39297 https://access.redhat.com/errata/RHSA-2026:39297 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:44231 https://access.redhat.com/errata/RHSA-2026:44231 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2026:43252 https://access.redhat.com/errata/RHSA-2026:43252 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2026:43226 https://access.redhat.com/errata/RHSA-2026:43226 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2026:54187 https://access.redhat.com/errata/RHSA-2026:54187 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:71542 https://access.redhat.com/errata/RHSA-2026:71542 |