CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages
CMS AuthEnvelopedData Processing May Accept Forged Messages
Other sources
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u7Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20240524git3e722403cd16-18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.7-2 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 3.0.21 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 3.4.6 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 3.5.7 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 3.6.3 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 4.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34182?
The severity of CVE-2026-34182 is critical with a CVSS score of 9.1.
How do I fix CVE-2026-34182?
To fix CVE-2026-34182, update OpenSSL to the latest version that addresses the vulnerability.
What issue does CVE-2026-34182 expose in OpenSSL?
CVE-2026-34182 exposes a potential for accepting forged messages due to insufficient input validation in CMS AuthEnvelopedData processing.
Which software versions are affected by CVE-2026-34182?
CVE-2026-34182 affects the OpenSSL library, including Debian's OpenSSL package.
What are the potential consequences of CVE-2026-34182?
The potential consequences of CVE-2026-34182 include various compromises from accepting malformed AuthEnvelopedData messages.