#1142474 rust-openssl: CVE-2026-45784

Package:
src:rust-openssl
Source:
src:rust-openssl
Submitter:
Salvatore Bonaccorso
Date:
2026-07-20 12:22:02 UTC
Severity:
normal
Tags:
#1142474#5
Date:
2026-07-20 12:20:38 UTC
From:
To:
Hi,

The following vulnerability was published for rust-openssl.

CVE-2026-45784[0]:
| rust-openssl provides OpenSSL bindings for the Rust programming
| language. From 0.10.50 until 0.10.80,
| CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs
| incorrectly sized output buffers when used with AES
| key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a
| non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of
| the caller's buffer or Vec, producing attacker-controllable heap
| corruption when the plaintext length is attacker-influenced. This
| issue is fixed in version 0.10.80.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-45784
https://www.cve.org/CVERecord?id=CVE-2026-45784
[1] https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq
[2] https://github.com/rust-openssl/rust-openssl/pull/2638
[3] https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7

Please adjust the affected versions in the BTS as needed.

REgards,
Salvatore