#1145172 openssl: CVE-2026-75803

Package:
src:openssl
Source:
src:openssl
Submitter:
Salvatore Bonaccorso
Date:
2026-08-26 18:48:02 UTC
Severity:
normal
Tags:
#1145172#5
Date:
2026-08-23 12:35:06 UTC
From:
To:
Hi,

The following vulnerability was published for openssl.

CVE-2026-75803[0]:
| Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-75803
https://www.cve.org/CVERecord?id=CVE-2026-75803
[1] https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a (openssl-4.0)
https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b (openssl-3.6)
https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34 (openssl-3.5)
https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42 (openssl-3.0)

Regards,
Salvatore

#1145172#14
Date:
2026-08-23 15:15:12 UTC
From:
To:
control: 1145172 found 3.0.0~~alpha1-1

Sebastian

#1145172#21
Date:
2026-08-25 20:29:11 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145172@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <sebastian@breakpoint.cc> (supplier of updated openssl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 25 Aug 2026 20:40:24 +0200
Source: openssl
Architecture: source
Version: 3.6.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel@alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Closes: 1143841 1144615 1145172
Changes:
 openssl (3.6.4-1) unstable; urgency=medium
 .
   * Import 3.6.4
     - CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
       INITIAL Packet")
     - CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
     - CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
       protectionAlg")
     - CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
       a Missing Certificate")
     - CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
       Epoch")
     - CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
       Validation")
     - CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
     - CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
       Exhaustion")
     - CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
       EVP_Cipher()") (Closes: #1145172)
     - CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
       Queue") (Closes: #1144615)
     - CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking") (Closes: #1143841)
Checksums-Sha1:
 d2744582a6895e5259ff20eef8d9cb657b9c1ad2 2675 openssl_3.6.4-1.dsc
 85aed0a4acf51f2e0d448310fd61099acf4d100a 55003802 openssl_3.6.4.orig.tar.gz
 987e36db37d0fcb54cd8a34fffa0259c90fb5cef 931 openssl_3.6.4.orig.tar.gz.asc
 e667314305cb4504a1ab9f9c7c7b28e16ded1e6b 51852 openssl_3.6.4-1.debian.tar.xz
Checksums-Sha256:
 c300906132d616fcce9b704f026fe2b15a83407c1b955914f0f8fe1dbb98b1af 2675 openssl_3.6.4-1.dsc
 9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef 55003802 openssl_3.6.4.orig.tar.gz
 2f957d2a61971714d256a6ed58a1336a687ee19859538514763f880aa89877de 931 openssl_3.6.4.orig.tar.gz.asc
 79b60079960546d53abe36a93b52c93a965af8ea8c814d59f3865bbb5ebc1371 51852 openssl_3.6.4-1.debian.tar.xz
Files:
 3fe339af785ae55358a60ea19dd6dd62 2675 utils optional openssl_3.6.4-1.dsc
 f771f53e0ce36d806d64e15f4d3a36d3 55003802 utils optional openssl_3.6.4.orig.tar.gz
 92607567a7850af08af082a3ff639bd4 931 utils optional openssl_3.6.4.orig.tar.gz.asc
 fbf687970996cb670773a19166a0c392 51852 utils optional openssl_3.6.4-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqN9pwACgkQBWQfF1cS
+luPHgv/TBeXuNXafQCkFy7ncYHsPRS/lXgVjWU0Fzto1xzAJ3LGC7iMuWDex4Y+
5TeW78JTidVw1Yh3g2i/290IJwFgNHPI6gX+l01IFVhRbEX0rhFBCsIZDGLZ9qbf
sqwRxSKTMZYj9oXXV8DKtrx8eExNeixUuEzvQBHwukZ4Ta90uPtPi4okcAYAYDkz
+to8+gUc6KJNW1BCFUDpC7AOPDHFNznEx1+NhjsO2Hm9r5LX8ag6r8s8fbtjr6Mb
KPCltrLE8yvHcYRjjL7zLSW5s947dryHDVFyQbZlkfrawXme6bcBIji2jxnyrn2C
r0JNLHknfuZQe3Yrbsn9uJoQsuhR7ObgpE8SUPct36RlBfWEgGFkP57SqZxGx5xn
GyChfVLwMgvwYUn11pfdP5xdthqQDhPG18pLmDnr0f7AuLrPVcInn3QLBYCd1BbN
4P3RJItAH9XPNBehpXd61Sa/ts3BfnqZjFk+piThUbJn3cm46rk3dN2RxpP/ve+p
sX5yqSog
=pgn/
-----END PGP SIGNATURE-----

#1145172#26
Date:
2026-08-25 20:29:22 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145172@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <sebastian@breakpoint.cc> (supplier of updated openssl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 25 Aug 2026 21:19:42 +0200
Source: openssl
Architecture: source
Version: 4.0.2-1
Distribution: experimental
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel@alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Closes: 1143841 1144615 1145172
Changes:
 openssl (4.0.2-1) experimental; urgency=medium
 .
   * Import 4.0.2
     - CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
       INITIAL Packet")
     - CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
     - CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
       protectionAlg")
     - CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
       a Missing Certificate")
     - CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
       Epoch")
     - CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
       Validation")
     - CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
     - CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
       Exhaustion")
     - CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
       EVP_Cipher()") (Closes: #1145172)
     - CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
       Queue") (Closes: #1144615)
     - CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking") (Closes: #1143841)
Checksums-Sha1:
 794c0bb4dd48c785968e761727e0a8468c8d77c5 2669 openssl_4.0.2-1.dsc
 236d35817b0adda5c07572ae24bcbe643b05c71d 55153883 openssl_4.0.2.orig.tar.gz
 084520b62aad0cbc3590b8384e00fd9f79c98c7f 931 openssl_4.0.2.orig.tar.gz.asc
 1f02deb39262b89837649dac0db9720eec231fdb 51124 openssl_4.0.2-1.debian.tar.xz
Checksums-Sha256:
 8e9ad392230018f1172b8a3ba299ea389d8b5ddafc6128ed8d8321d04eee0dda 2669 openssl_4.0.2-1.dsc
 736b467530f916737b7031310ccb21d8218c6229e61e8e160cd1d3458cd543a8 55153883 openssl_4.0.2.orig.tar.gz
 2eade0aa5a3734301b6e53dc25b5c681a4aec7a2d3b2632c74bbac9b65cb9e60 931 openssl_4.0.2.orig.tar.gz.asc
 3a7cdef57c3a8dd884d460ab50fbe5eb7c6a825106312e5ea966ce4cca4d9941 51124 openssl_4.0.2-1.debian.tar.xz
Files:
 a8a93931fe4324de5fe358ec5c824888 2669 utils optional openssl_4.0.2-1.dsc
 9d256ddfa581e1982c005ab03890754d 55153883 utils optional openssl_4.0.2.orig.tar.gz
 893cd5f159d68140ab9011c07adfae84 931 utils optional openssl_4.0.2.orig.tar.gz.asc
 c00ee3a33f8ae40a85c2c5d076fec94e 51124 utils optional openssl_4.0.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqN9pkACgkQBWQfF1cS
+lsQNAv/VkrkQHQSnatAnghMENkaLnk7pYnpTn5DjaRhrdcD+quGFDVx0pyO0leY
C9FX2yDx42OzAHVOQRWsuP6mP/CtvfNTXuLJaZFKwolQ2nXx23ZDic8/evf0CFIn
9Ddwu+vN6DIvK9fH40ivWyCIo6eig2xVAFdgM9zIkrNOr6iLMn88IeRASQyPvD+v
ryFIC18La+rPBIxmrVilVpZPI/P8j4g5bQN6g4cRXgXP4HWrAxot2OjsHdmrYEoZ
05aicp8eoMyL1MpfZKUqiZacL7JiM63e/6z8V4lNeaeLx24o6nztM+bQtfeGpCmS
jnVW+Q0oY4p0vbQ5FuZgWZYRDQ+GMVMz1K7Y3J7SbhqiHNFog06c2TqYua1dY8PA
S+cSDvCtwmyMytHodWs0KHOdjITaNtlgnvp/nlWR8Ut8BaLmOnMVo6FJp50PP+CW
i7nvFU6JOPkVaa39WirI3v+ZCJjoKDddcOowS56BA4eDP6nKw71d/BqcoxV2hwMs
EGZXnE+f
=WxoT
-----END PGP SIGNATURE-----

#1145172#31
Date:
2026-08-26 18:47:07 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145172@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <sebastian@breakpoint.cc> (supplier of updated openssl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 23 Aug 2026 17:26:22 +0200
Source: openssl
Architecture: source
Version: 3.5.7-1~deb13u2
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel@alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Closes: 1144615 1145172
Changes:
 openssl (3.5.7-1~deb13u2) trixie-security; urgency=medium
 .
   * CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
     INITIAL Packet")
   * CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
   * CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
     protectionAlg")
   * CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
     a Missing Certificate")
   * CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
     Epoch")
   * CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
     Validation")
   * CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
   * CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
     Exhaustion")
   * CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
     EVP_Cipher()") (Closes: #1145172)
   * CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
     Queue") (Closes: #1144615)
Checksums-Sha1:
 3ca57150dc1772933fd41379d021de9a77b83de9 2707 openssl_3.5.7-1~deb13u2.dsc
 53d331880fbde8e6fe25870d5325a61201f6264d 53153930 openssl_3.5.7.orig.tar.gz
 9408998095f984b36591732286ef1df1ba7ce492 833 openssl_3.5.7.orig.tar.gz.asc
 6d1177d59ef985cff4b6baef95ae748ec724af12 74836 openssl_3.5.7-1~deb13u2.debian.tar.xz
Checksums-Sha256:
 25904642004d30c5c3da4642a72a7d09f8d9eb6e5ce62dab53c0371114faf8f2 2707 openssl_3.5.7-1~deb13u2.dsc
 a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8 53153930 openssl_3.5.7.orig.tar.gz
 d3d082bee3f658c31db53af625eceecf29d777c7010394bed5787ebcc98abdf2 833 openssl_3.5.7.orig.tar.gz.asc
 593a47654ead460a3b609503733f80bef552ff0802799d3b47784faacc50809f 74836 openssl_3.5.7-1~deb13u2.debian.tar.xz
Files:
 81887cbcbcfffb723ad8f7dcfdcaef70 2707 utils optional openssl_3.5.7-1~deb13u2.dsc
 36608cd5445f708d0c2200aea9682c35 53153930 utils optional openssl_3.5.7.orig.tar.gz
 1550a37dc3382ec617b5fd7d4140b92c 833 utils optional openssl_3.5.7.orig.tar.gz.asc
 1345084467bf31d9c7caf40647744577 74836 utils optional openssl_3.5.7-1~deb13u2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqLE+4ACgkQBWQfF1cS
+ls/WgwAmzlbjcsP6qMq6l4IPgT2VHHG69FRWTJbnELXQ2dnrnknBJR9P/qjq00M
qV302bCH0ryaCYZAfWfYIiYwvTU+pP43iqjpTRKjENh0UDSgx5FiSWn+6i2Jcbl6
QCvx1oJY+1GsGxDoblIoG/hOXwyX8h2T2o3aA+F+rc3A5gJlEm3+GrauE3oM5KRP
UiJCK9yX194VyweZdV3gJmAUzhQ/DhZz2z+a6dMZuaJsTf0ZKtPGL2DLKT7DVHtt
EscEOLKZO96i/6QU4OQDjkLN+RVZ7rsA/uqXqvbnfKqFcEYqOD7WfM/T8ItKi26/
ZvBv23SlhiKbgvRmyJhz5j6F1V9qCrId1dGoGRS2H4cPuxobyFHat1ohbFXJxBxf
RTAc7uFGhgZMebvfFNJj0sc55U1dIqwXQb5ZoyLZPRdUIQYUcYtydoEgA1q6OvnX
qqtDwqjvhSW6P7uvlX9/fFi9k3mE1ihKtBu4rkk3wOUVaOFsBSWIrKjysM0LWqiE
EdZMkxL9
=eCc/
-----END PGP SIGNATURE-----