Back

MEDIUM

rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers

Published Jul 17, 2026

Description

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.

Affected products

Remediation

Red Hat statement

This Moderate flaw in `rust-openssl` can lead to heap corruption when processing data with AES key-wrap-with-padding ciphers. An attacker able to influence the plaintext length could trigger an out-of-bounds write, potentially causing a denial of service or data integrity issues. Exploitation requires the use of these specific ciphers, limiting the attack surface.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 17, 2026
Updated Jul 20, 2026
Reserved May 13, 2026
CISA Vulnrichment
Updated Jul 20, 2026
NVD
Status Analyzed
Modified Jul 29, 2026
Red Hat
Severity Moderate
Public date Jul 17, 2026
GHSA-PHQJ-4MHP-Q6MQ