Home / mailings [USN-8678-1] OpenSSL vulnerabilities
Posted on 25 August 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8678-1
August 25, 2026
openssl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
It was discovered that OpenSSL incorrectly handled the QUIC server incoming
channel queue. A remote attacker could possibly use this issue to cause
OpenSSL to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)
It was discovered that OpenSSL incorrectly handled signature algorithm
selection when using Raw Public Keys. A remote attacker could possibly use
this issue to cause OpenSSL to crash, resulting in a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)
It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet
processing. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-18798)
It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)
It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)
It was discovered that OpenSSL incorrectly validated the sender
distinguished name in CMP response messages. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)
It was discovered that OpenSSL incorrectly limited the growth of an
internal certificate cache used during CMP operations. A remote attacker
could possibly use this issue to cause OpenSSL to use excessive resources,
leading to a denial of service. (CVE-2026-63074)
It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet
retention. A remote attacker could possibly use this issue to cause OpenSSL
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-63075)
It was discovered that OpenSSL incorrectly handled CMP protection algorithm
validation. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)
It was discovered that OpenSSL incorrectly verified authentication tags
when using certain AEAD ciphers via the EVP_Cipher() interface. An attacker
could possibly use this issue to perform AEAD forgery attacks.
(CVE-2026-75803)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libssl3t64 3.5.5-1ubuntu3.4
openssl 3.5.5-1ubuntu3.4
Ubuntu 24.04 LTS
libssl3t64 3.0.13-0ubuntu3.15
openssl 3.0.13-0ubuntu3.15
Ubuntu 22.04 LTS
libssl3 3.0.2-0ubuntu1.29
openssl 3.0.2-0ubuntu1.29
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8678-1
CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874,
CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075,
CVE-2026-63076, CVE-2026-75803
Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4
https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15
https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29
--===============7596000549730101197==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
