CVE-2026-45784: rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
CipherCtxRef::cipherupdateinplace incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVPaes{128,192,256}wrappad). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced.
This only impacts users using AES key-wrap-with-padding ciphers.
This method was missed in the fix for GHSA-xv59-967r-8726
Other sources
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipherupdateinplace in openssl/src/cipherctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVPaes{128,192,256}wrappad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45784?
CVE-2026-45784 has a risk rating of 62, indicating a moderate severity vulnerability.
How do I fix CVE-2026-45784?
To fix CVE-2026-45784, you should update to the latest version of rust-openssl that includes the patch for this vulnerability.
What causes CVE-2026-45784?
CVE-2026-45784 is caused by incorrectly sized output buffers in the CipherCtxRef::cipher_update_inplace function when using AES key-wrap-with-padding ciphers.
What impact does CVE-2026-45784 have on my application?
The impact of CVE-2026-45784 can lead to heap corruption, potentially allowing an attacker to control memory beyond the allocated buffers.
Who is affected by CVE-2026-45784?
CVE-2026-45784 affects applications using rust-openssl with AES key-wrap-with-padding ciphers that do not handle non-multiple-of-8 inputs correctly.