CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption
Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kekunwrapkey().
Other sources
Out-of-Bounds Read in CMS Password-Based Decryption
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20240524git3e722403cd16-18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.7-3 - Upgrade
Upgrade
OpenSSL 1.0.2to a version that resolves this vulnerability.Fixed in 1.0.2zq - Upgrade
Upgrade
OpenSSL 1.1.1to a version that resolves this vulnerability.Fixed in 1.1.1zh - Upgrade
Upgrade
OpenSSL 3.0to a version that resolves this vulnerability.Fixed in 3.0.21 - Upgrade
Upgrade
OpenSSL 3.4to a version that resolves this vulnerability.Fixed in 3.4.6 - Upgrade
Upgrade
OpenSSL 3.5to a version that resolves this vulnerability.Fixed in 3.5.7 - Upgrade
Upgrade
OpenSSL 3.6to a version that resolves this vulnerability.Fixed in 3.6.3 - Upgrade
Upgrade
OpenSSL 4.0to a version that resolves this vulnerability.Fixed in 4.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9076?
CVE-2026-9076 has a high severity rating of 7.5 on the CVSS scale.
How do I fix CVE-2026-9076?
To mitigate CVE-2026-9076, you should update to the latest version of OpenSSL that addresses this vulnerability.
What type of vulnerability is CVE-2026-9076?
CVE-2026-9076 is an out-of-bounds read vulnerability in the CMS password-based decryption process.
Which software is affected by CVE-2026-9076?
CVE-2026-9076 affects OpenSSL and specifically the Debian implementation of OpenSSL.
What are the potential impacts of exploiting CVE-2026-9076?
Exploiting CVE-2026-9076 could allow an attacker to cause a denial of service by triggering a heap out-of-bounds read.