Bug 2523425 (CVE-2026-75803) - CVE-2026-75803 openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher()
Summary: CVE-2026-75803 openssl: openssl: AEAD forgeries possible with empty ciphertex...
Keywords:
Status: NEW
Alias: CVE-2026-75803
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2535881 2535883 2535884 2535886 2535887 2535888 2535890 2535892 2535894 2535896 2535897 2535898 2535899 2535900 2535882 2535885 2535889 2535891 2535893 2535895
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-25 13:23 UTC by OSIDB Bzimport
Modified: 2026-09-17 11:20 UTC (History)
123 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-25 13:23:49 UTC
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty
ciphertext can report success without verifying the supplied authentication
tag when the operation is finalized by calling the EVP_Cipher() function.

Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and
expecting the call to check the AEAD tag may accept forged messages.

CWE: CWE-354 (Improper Validation of Integrity Check Value)

Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one
shot encryption and decryption call. It also verifies the AEAD tag after the
decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers
it skipped the AEAD tag verification when an empty ciphertext was passed to
the function. The callers of this function might believe that a successful
return indicates a valid AEAD tag for these ciphers, even when that has not
truly been validated in this case.

FIPS impact: no
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE
as the affected algorithms are not FIPS approved and thus not implemented
in the FIPS module.


Note You need to log in before you can comment on or make changes to this bug.