Home / mailingsPDF  

[USN-8678-3] OpenSSL vulnerability

Posted on 31 August 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8678-3
August 31, 2026

openssl vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS

Summary:

USN-8678-1 contained an incomplete fix for Ubuntu 26.04 LTS.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

USN-8673-1 fixed vulnerabilities in OpenSSL. The update inadvertently left
out the fix for CVE-2026-75803 in Ubuntu 26.04 LTS. This update fixes the
problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that OpenSSL incorrectly handled the QUIC server incoming
channel queue. A remote attacker could possibly use this issue to cause
OpenSSL to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)

It was discovered that OpenSSL incorrectly handled signature algorithm
selection when using Raw Public Keys. A remote attacker could possibly use
this issue to cause OpenSSL to crash, resulting in a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)

It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet
processing. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-18798)

It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)

It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)

It was discovered that OpenSSL incorrectly validated the sender
distinguished name in CMP response messages. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)

It was discovered that OpenSSL incorrectly limited the growth of an
internal certificate cache used during CMP operations. A remote attacker
could possibly use this issue to cause OpenSSL to use excessive resources,
leading to a denial of service. (CVE-2026-63074)

It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet
retention. A remote attacker could possibly use this issue to cause OpenSSL
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-63075)

It was discovered that OpenSSL incorrectly handled CMP protection algorithm
validation. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)

It was discovered that OpenSSL incorrectly verified authentication tags
when using certain AEAD ciphers via the EVP_Cipher() interface. An attacker
could possibly use this issue to perform AEAD forgery attacks.
(CVE-2026-75803)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libssl3t64 3.5.5-1ubuntu3.5
openssl 3.5.5-1ubuntu3.5

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8678-3
https://ubuntu.com/security/notices/USN-8678-2
https://ubuntu.com/security/notices/USN-8678-1
CVE-2026-75803

Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.5

--===============5519359046939851190==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP