Hi,
The following vulnerability was published for rust-openssl.
CVE-2026-45784[0]:
| rust-openssl provides OpenSSL bindings for the Rust programming
| language. From 0.10.50 until 0.10.80,
| CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs
| incorrectly sized output buffers when used with AES
| key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a
| non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of
| the caller's buffer or Vec, producing attacker-controllable heap
| corruption when the plaintext length is attacker-influenced. This
| issue is fixed in version 0.10.80.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-45784
https://www.cve.org/CVERecord?id=CVE-2026-45784
[1] https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq
[2] https://github.com/rust-openssl/rust-openssl/pull/2638
[3] https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7
Please adjust the affected versions in the BTS as needed.
REgards,
Salvatore