Ubuntu alert USN-8414-2 (openssl, openssl1.0)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8414-2] OpenSSL vulnerabilities | |
| Date: | Tue, 09 Jun 2026 19:33:31 +0000 | |
| Message-ID: | <E1wX2CZ-0002pL-2N@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8414-2 June 09, 2026 openssl, openssl1.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: USN-8414-1 fixed several vulnerabilities in OpenSSL. Software Description: - openssl: Secure Socket Layer (SSL) cryptographic library and tools - openssl1.0: Secure Socket Layer (SSL) cryptographic library and tools Details: USN-8414-1 fixed several vulnerabilities in OpenSSL. This update provides the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: Frank Buss discovered that OpenSSL had a heap buffer over-read in ASN.1 content parsing. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service, or obtain sensitive information. (CVE-2026-34180) Asim Viladi Oglu Manizada and Alex Gaynor discovered that OpenSSL could accept forged CMS AuthEnvelopedData messages. An attacker could possibly use this issue to bypass message authentication checks. (CVE-2026-34182) Mayank Jangid, Kushal Khemka, Hari Priandana, Bhabani Sankar Das, and Qifan Zhang discovered that OpenSSL had a possible NULL dereference in password- based CMS decryption. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2026-42766) Zhanpeng Liu, Guannan Wang, and Guancheng Li discovered that OpenSSL had a NULL pointer dereference in CRMF EncryptedValue decryption. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2026-42767) Thai Duong discovered that OpenSSL had a heap use-after-free in PKCS7_verify(). An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-45447) Zehua Qiao and Jinwen He discovered that OpenSSL had a possible heap buffer overflow in ASN.1 multibyte string conversion. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-7383) Bhabani Sankar Das discovered that OpenSSL had an out-of-bounds read in CMS password-based decryption. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2026-9076) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS openssl 1.1.1f-1ubuntu2.24+esm4 Available with Ubuntu Pro Ubuntu 18.04 LTS openssl 1.1.1-1ubuntu2.1~18.04.23+esm9 Available with Ubuntu Pro openssl1.0 1.0.2n-1ubuntu5.13+esm5 Available with Ubuntu Pro Ubuntu 16.04 LTS openssl 1.0.2g-1ubuntu4.20+esm16 Available with Ubuntu Pro Ubuntu 14.04 LTS openssl 1.0.1f-1ubuntu2.27+esm14 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8414-2 https://ubuntu.com/security/notices/USN-8414-1 CVE-2026-34180, CVE-2026-34182, CVE-2026-42766, CVE-2026-45447, CVE-2026-7383, CVE-2026-9076
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmooZ2YACgkQcpJm3tlz hgEP7A/9E8lopwj1rku4U4pZIf6DC244u/ZYYzDMlTGuM/u0shXqheHqWRgdEFke N3NMfd1XI08vU+sANn2yGKs8XSBa7GKnR0egrSw6YtS59TtE/cMB9XPYt3KkNMm9 v3LxK2jyXfwwGSdPe4GpzKp7/dcqYIVK9aLP+ZNlY/pGykUtq/EzhI6NHK7IhAVB YSz9+4jIF71hjZRTGRmeSBQOcvU96/UsFsJly+6C/8rkmxbTnflUOCkPlLrKzafU 4ZHMl+ZspCrJBKMobTSq+/wDdAH0U67WKQenSWlIKiZ3pydexEKzXVp3VgS//1d4 bXkanj5y0JcBmKHT8NPy5ebezRP3NJv9mKBrfmyDrP6U3lB4c2Pl4AArRW3EMBbw 3oh3aS5QpF3QFmfqBrnNhc+H+o9IYriL7sRHgKh0jQi5ZTfSKNrGxPUzeFk7O0I6 yhPJPlaFesEqLp0Q0C+JifQa2YiupGKEXnLKbtnwGtAkVIOqv5v9RjC6GzEv3lMJ YU7Z0pmcta0n1Am/uSiM4zmj6NqktstedtDXPOJX61nY66v4wBr/6cjgH+ChKvtw 4Tgv/15G275m2G7v1es6PStveyudCPtnrlVUDhrSUqsxNHNlHBs1l/Actb992JlX Q+M5DTKsfTVO3IMwqeFX4Y0/kAcUm6fgINkagDzu1bM3EpsO6pM= =bR2q -----END PGP SIGNATURE-----
