Home / mailingsPDF  

[USN-8847-2] OpenSSL vulnerabilities

Posted on 30 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8847-2
September 29, 2026

openssl, openssl1.0 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in OpenSSL.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
- openssl1.0: Secure Socket Layer (SSL) cryptographic library and tools

Details:

USN-8847-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that OpenSSL incorrectly handled certain certificate
revocation list distribution point names. An attacker could possibly use
this issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. (CVE-2026-35189)

It was discovered that OpenSSL incorrectly implemented scalar
multiplication for non-NIST elliptic curves. An attacker could possibly use
this issue to perform a timing side-channel attack and obtain
sensitive information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2026-54872)

It was discovered that OpenSSL incorrectly implemented SM2 signature
generation. An attacker could possibly use this issue to perform a
timing side-channel attack and obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-77696)

It was discovered that OpenSSL incorrectly handled DTLS retransmission
of handshake messages. An attacker could possibly use this issue to
cause incorrect handshake behavior or a denial of service.
(CVE-2026-84782)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
libssl1.1 1.1.1f-1ubuntu2.24+esm6
Available with Ubuntu Pro
openssl 1.1.1f-1ubuntu2.24+esm6
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libssl1.0.0 1.0.2n-1ubuntu5.13+esm7
Available with Ubuntu Pro
libssl1.1 1.1.1-1ubuntu2.1~18.04.23+esm11
Available with Ubuntu Pro
openssl 1.1.1-1ubuntu2.1~18.04.23+esm11
Available with Ubuntu Pro
openssl1.0 1.0.2n-1ubuntu5.13+esm7
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libssl1.0.0 1.0.2g-1ubuntu4.20+esm19
Available with Ubuntu Pro
openssl 1.0.2g-1ubuntu4.20+esm19
Available with Ubuntu Pro

Ubuntu 14.04 LTS
libssl1.0.0 1.0.1f-1ubuntu2.27+esm17
Available with Ubuntu Pro
openssl 1.0.1f-1ubuntu2.27+esm17
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8847-2
https://ubuntu.com/security/notices/USN-8847-1
CVE-2026-35189, CVE-2026-54872, CVE-2026-77696, CVE-2026-84782

--===============4940716709299848466==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP