rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Published Jul 17, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.13%
Description
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.
Affected products
-
- Version >= 0.10.50, < 0.10.80StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rust-Openssl | Rust-Openssl | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate flaw in `rust-openssl` can lead to heap corruption when processing data with AES key-wrap-with-padding ciphers. An attacker able to influence the plaintext length could trigger an out-of-bounds write, potentially causing a denial of service or data integrity issues. Exploitation requires the use of these specific ciphers, limiting the attack surface.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-45784 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2501931 Issue Tracking
- https://github.com/advisories/GHSA-phqj-4mhp-q6mq Advisory
- https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7 x_refsource_MISCPatch
- https://github.com/rust-openssl/rust-openssl/pull/2638 x_refsource_MISCIssue TrackingPatch
- https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.80 x_refsource_MISCProductRelease Notes
- https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-45784
- https://www.cve.org/CVERecord?id=CVE-2026-45784
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-45784 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2501931 | Issue Tracking | |
| https://github.com/advisories/GHSA-phqj-4mhp-q6mq | Advisory | |
| https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7 | x_refsource_MISCPatch | |
| https://github.com/rust-openssl/rust-openssl/pull/2638 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.80 | x_refsource_MISCProductRelease Notes | |
| https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45784 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-45784 |
Change history (0)
No recorded changes yet.