A vulnerability, which was classified as critical, was found in rust-openssl up to 0.10.77. This vulnerability affects the function set_psk_client_callback/set_psk_server_callback/set_cookie_generate_cb/set_stateless_cookie_generate_cb. Executing a manipulation can lead to buffer over-read. The identification of this vulnerability is CVE-2026-41898. The attack may be launched remotely.
| Vendor | Product | Versions |
|---|---|---|
| rust-openssl | rust-openssl | >= 0.9.24, < 0.10.78, 0.10.77 |
Updated patch version to 0.10.78 and added new CVE IDs and relevant tags.
Updated vendor and product to rust-openssl, changed severity to CRITICAL, and added affected version 0.10.77.
Initial creation