系微安全保證

最新安全公告

INSYDE-SA-2026008

Product

CVSS Score

Original Date

Last Revised

InsydeH2O

See in description

2026-09-08

Summary

Code change to accommodate OpenSSL 3.0.21

Vulnerability Details

CVSS Vector: See in description

InsydeH2O code change to accommodate OpenSSL 3.0.21 which addresses following vulnerabilities.

https://www.cve.org/CVERecord?id=CVE-2026-45447
Description: Heap use-after-free in PKCS7_verify().
CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

https://www.cve.org/CVERecord?id=CVE-2026-34182
Description: CMS AuthEnvelopedData processing may accept forged messages.
CVSS: 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

https://www.cve.org/CVERecord?id=CVE-2026-45445
Description: AES-OCB IV ignored on EVP_Cipher() path.
CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

https://www.cve.org/CVERecord?id=CVE-2026-7383
Description: Possible heap buffer overflow in ASN.1 multibyte string conversion.
CVSS: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

https://www.cve.org/CVERecord?id=CVE-2026-9076
Description: Out-of-bounds read in CMS password-based decryption.
CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

https://www.cve.org/CVERecord?id=CVE-2026-34180
Description: Heap buffer over-read in ASN.1 content parsing.
CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

https://www.cve.org/CVERecord?id=CVE-2026-42766
Description: Possible NULL dereference in password-dased CMS decryption.
CVSS: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

https://www.cve.org/CVERecord?id=CVE-2026-42770
Description: FFC-DH peer validation uses attacker-supplied q.
CVSS: 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

https://www.cve.org/CVERecord?id=CVE-2026-45446
Description: Incorrect tag processing for empty messages in AES-GCM-SIV and AES-SIV modes.
CVSS: 3.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)

Solution Information

Kernel 5.3: Version 05.3A.25
Kernel 5.4: Version 05.48.25
Kernel 5.5: Version 05.56.25
Kernel 5.6: Version 05.63.25

Acknowledgements

Revision History

Revision #

Date

Description

1

2026-09-08

Initial Release