Home / mailings [USN-8678-2] OpenSSL, OpenSSL 1.0 vulnerabilities
Posted on 26 August 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8678-2
August 25, 2026
openssl, openssl1.0 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in OpenSSL and OpenSSL 1.0.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
- openssl1.0: Secure Socket Layer (SSL) cryptographic library and tools
Details:
USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
In addition, this update also fixes the following issues that were
not previously addressed in those releases:
It was discovered that OpenSSL incorrectly handled TLS handshake
message buffering. A remote attacker could possibly use this issue to
cause OpenSSL to consume excessive memory, leading to a denial of
service. (LP: #2161371)
It was discovered that OpenSSL incorrectly handled session cache
management when processing TLSv1.3 sessions. A remote attacker could
possibly use this issue to cause OpenSSL to consume excessive memory,
leading to a denial of service. This issue only affected OpenSSL 1.1.1
on Ubuntu 18.04 LTS. (CVE-2024-2511)
It was discovered that OpenSSL incorrectly handled the SSL_select_next_proto
function when called with an empty client protocol list. A remote attacker
could possibly use this issue to cause OpenSSL to disclose private memory
contents to the peer, leading to a loss of confidentiality. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-5535)
Original advisory details:
It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)
It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
libssl1.1 1.1.1f-1ubuntu2.24+esm5
Available with Ubuntu Pro
openssl 1.1.1f-1ubuntu2.24+esm5
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libssl1.0.0 1.0.2n-1ubuntu5.13+esm6
Available with Ubuntu Pro
libssl1.1 1.1.1-1ubuntu2.1~18.04.23+esm10
Available with Ubuntu Pro
openssl 1.1.1-1ubuntu2.1~18.04.23+esm10
Available with Ubuntu Pro
openssl1.0 1.0.2n-1ubuntu5.13+esm6
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libssl1.0.0 1.0.2g-1ubuntu4.20+esm18
Available with Ubuntu Pro
openssl 1.0.2g-1ubuntu4.20+esm18
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libssl1.0.0 1.0.1f-1ubuntu2.27+esm16
Available with Ubuntu Pro
openssl 1.0.1f-1ubuntu2.27+esm16
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8678-2
https://ubuntu.com/security/notices/USN-8678-1
CVE-2024-2511, CVE-2024-5535, CVE-2026-54874, CVE-2026-63072
--===============0835077075725477515==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
