CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
Other sources
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u7Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.7-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.20 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.6.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45446?
The severity of CVE-2026-45446 is classified as medium with a CVSS score of 4.8.
What vulnerabilities are associated with CVE-2026-45446?
CVE-2026-45446 is associated with incorrect tag processing for empty messages in AES-GCM-SIV and AES-SIV modes.
How does CVE-2026-45446 affect AES-GCM-SIV and AES-SIV modes?
CVE-2026-45446 affects AES-GCM-SIV and AES-SIV modes by mishandling the authentication process for empty messages.
How can I mitigate the risks posed by CVE-2026-45446?
Mitigation strategies for CVE-2026-45446 involve updating to a patched version of OpenSSL that addresses the tag processing issues.
Which software versions are impacted by CVE-2026-45446?
CVE-2026-45446 impacts OpenSSL and Debian's version of OpenSSL that utilize AES-SIV and AES-GCM-SIV modes.