Bug 2530240 (CVE-2026-53938) - CVE-2026-53938 cjose: cjose: Heap buffer overflow in AES Key Wrap decryption leads to denial of service
Summary: CVE-2026-53938 cjose: cjose: Heap buffer overflow in AES Key Wrap decryption ...
Keywords:
Status: NEW
Alias: CVE-2026-53938
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2530534
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-08 23:31 UTC by OSIDB Bzimport
Modified: 2026-10-07 13:06 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:73017 0 None None None 2026-09-29 06:05:58 UTC
Red Hat Product Errata RHSA-2026:73018 0 None None None 2026-09-29 06:13:01 UTC
Red Hat Product Errata RHSA-2026:73128 0 None None None 2026-09-29 12:28:21 UTC
Red Hat Product Errata RHSA-2026:73129 0 None None None 2026-09-29 11:45:08 UTC
Red Hat Product Errata RHSA-2026:77369 0 None None None 2026-10-07 13:06:55 UTC
Red Hat Product Errata RHSA-2026:77370 0 None None None 2026-10-07 08:46:31 UTC
Red Hat Product Errata RHSA-2026:77371 0 None None None 2026-10-07 08:37:08 UTC
Red Hat Product Errata RHSA-2026:77372 0 None None None 2026-10-07 08:43:53 UTC

Description OSIDB Bzimport 2026-09-08 23:31:17 UTC
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted Key) before unwrapping it into a fixed-size, heap-allocated Content Encryption Key (CEK) buffer. A remote, unauthenticated attacker who can submit a crafted JWE to an application that decrypts it with an AES-KW symmetric key can trigger an out-of-bounds heap write, corrupting the heap. This leads at minimum to a crash (denial of service) and, depending on the heap layout and allocator, may be leverageable for further memory-corruption impact. `cjose_jwe_import()` / `cjose_jwe_decrypt()` are pre-authentication entry points: they parse and process fully attacker-controlled input. Upgrade to cjose 0.6.2.5 to receive a patch. If upgrading is not immediately possible, reject the AES Key Wrap algorithms (`A128KW`/`A192KW`/`A256KW`) for untrusted JWEs at the application layer.

Comment 2 Jon Orris 2026-09-29 06:05:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:73017 https://access.redhat.com/errata/RHSA-2026:73017

Comment 3 Jon Orris 2026-09-29 06:13:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:73018 https://access.redhat.com/errata/RHSA-2026:73018

Comment 4 Jon Orris 2026-09-29 11:45:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:73129 https://access.redhat.com/errata/RHSA-2026:73129

Comment 5 Jon Orris 2026-09-29 12:28:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:73128 https://access.redhat.com/errata/RHSA-2026:73128

Comment 6 Jon Orris 2026-10-07 08:37:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:77371 https://access.redhat.com/errata/RHSA-2026:77371

Comment 7 Jon Orris 2026-10-07 08:37:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:77371 https://access.redhat.com/errata/RHSA-2026:77371

Comment 8 Jon Orris 2026-10-07 08:43:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:77372 https://access.redhat.com/errata/RHSA-2026:77372

Comment 9 Jon Orris 2026-10-07 08:43:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:77372 https://access.redhat.com/errata/RHSA-2026:77372

Comment 10 Jon Orris 2026-10-07 08:46:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:77370 https://access.redhat.com/errata/RHSA-2026:77370

Comment 11 Jon Orris 2026-10-07 13:06:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:77369 https://access.redhat.com/errata/RHSA-2026:77369


Note You need to log in before you can comment on or make changes to this bug.