Skip to content

libressl-v4.1.1

tagged this 30 Sep 12:54
cms_RecipientInfo_pwri_crypt: plug leak of kekalg
cms: fix incorrect length check in kek_unwrap_key()

An incorrect length check can result in a 4-byte overwrite and an
8-byte overread.

From Stanislav Fort and Viktor Dukhovni via OpenSSL.
CVE-2025-9230.

ok jsing

this is errata/7.7/010_libcrypto.patch.sig
Assets 2
Loading