Home / mailings [USN-8678-3] OpenSSL vulnerability
Posted on 31 August 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8678-3
August 31, 2026
openssl vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
Summary:
USN-8678-1 contained an incomplete fix for Ubuntu 26.04 LTS.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
USN-8673-1 fixed vulnerabilities in OpenSSL. The update inadvertently left
out the fix for CVE-2026-75803 in Ubuntu 26.04 LTS. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenSSL incorrectly handled the QUIC server incoming
channel queue. A remote attacker could possibly use this issue to cause
OpenSSL to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)
It was discovered that OpenSSL incorrectly handled signature algorithm
selection when using Raw Public Keys. A remote attacker could possibly use
this issue to cause OpenSSL to crash, resulting in a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)
It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet
processing. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-18798)
It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)
It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)
It was discovered that OpenSSL incorrectly validated the sender
distinguished name in CMP response messages. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)
It was discovered that OpenSSL incorrectly limited the growth of an
internal certificate cache used during CMP operations. A remote attacker
could possibly use this issue to cause OpenSSL to use excessive resources,
leading to a denial of service. (CVE-2026-63074)
It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet
retention. A remote attacker could possibly use this issue to cause OpenSSL
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-63075)
It was discovered that OpenSSL incorrectly handled CMP protection algorithm
validation. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)
It was discovered that OpenSSL incorrectly verified authentication tags
when using certain AEAD ciphers via the EVP_Cipher() interface. An attacker
could possibly use this issue to perform AEAD forgery attacks.
(CVE-2026-75803)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libssl3t64 3.5.5-1ubuntu3.5
openssl 3.5.5-1ubuntu3.5
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8678-3
https://ubuntu.com/security/notices/USN-8678-2
https://ubuntu.com/security/notices/USN-8678-1
CVE-2026-75803
Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.5
--===============5519359046939851190==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
