Insyde's Security Pledge
Recent Security Advisories

INSYDE-SA-2026008
Product
CVSS Score
Original Date
Last Revised
InsydeH2O
See in description
2026-09-08
Summary
Code change to accommodate OpenSSL 3.0.21
Vulnerability Details
CVSS Vector: See in description
InsydeH2O code change to accommodate OpenSSL 3.0.21 which addresses following vulnerabilities.
https://www.cve.org/CVERecord?id=CVE-2026-45447
Description: Heap use-after-free in PKCS7_verify().
CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
https://www.cve.org/CVERecord?id=CVE-2026-34182
Description: CMS AuthEnvelopedData processing may accept forged messages.
CVSS: 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
https://www.cve.org/CVERecord?id=CVE-2026-45445
Description: AES-OCB IV ignored on EVP_Cipher() path.
CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
https://www.cve.org/CVERecord?id=CVE-2026-7383
Description: Possible heap buffer overflow in ASN.1 multibyte string conversion.
CVSS: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
https://www.cve.org/CVERecord?id=CVE-2026-9076
Description: Out-of-bounds read in CMS password-based decryption.
CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
https://www.cve.org/CVERecord?id=CVE-2026-34180
Description: Heap buffer over-read in ASN.1 content parsing.
CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
https://www.cve.org/CVERecord?id=CVE-2026-42766
Description: Possible NULL dereference in password-dased CMS decryption.
CVSS: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
https://www.cve.org/CVERecord?id=CVE-2026-42770
Description: FFC-DH peer validation uses attacker-supplied q.
CVSS: 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
https://www.cve.org/CVERecord?id=CVE-2026-45446
Description: Incorrect tag processing for empty messages in AES-GCM-SIV and AES-SIV modes.
CVSS: 3.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Solution Information
Kernel 5.3: Version 05.3A.25
Kernel 5.4: Version 05.48.25
Kernel 5.5: Version 05.56.25
Kernel 5.6: Version 05.63.25
Acknowledgements
Revision History
Revision #
Date
Description
1
2026-09-08
Initial Release