Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-9076EXPLOITEDPATCHED
openssl · openssl

Out-of-Bounds Read in CMS Password-Based Decryption

Description

Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker. The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen. Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds. The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator. The FIPS modules are not affected by this issue.

Affected Products

VendorProductVersions
opensslopenssl4.0.0, 3.6.0, 3.5.0, 3.4.0, 3.0.0, 1.1.1, 1.0.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmapp connect enterprisecert_advisory90%
oraclesolariscert_advisory90%
splunksplunk enterprisecert_advisory90%

References

  • https://openssl-library.org/news/secadv/20260609.txt(vendor-advisory)
  • https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0(patch)
  • https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26(patch)
  • https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98(patch)
  • https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb(patch)
  • https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6(patch)

Related News (9 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] Splunk Splunk Enterprise: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits Splunk (20 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR32d ago
Multiples vulnérabilités dans Oracle Database Server (23 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories32d ago
[NEU] [hoch] Oracle Solaris Drittanbieterkomponenten: Mehrere Schwachstellen
→ No new info (linked only)
Tier A
Microsoft MSRC72d ago
CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption
→ No new info (linked only)
Tier B
CERT-FR75d ago
Multiples vulnérabilités dans OpenSSL (10 juin 2026)
→ No new info (linked only)
Tier C
VulDB75d ago
CVE-2026-9076 | OpenSSL up to 4.0.0 kek_unwrap_key out-of-bounds
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.0.13.6.33.5.73.4.63.0.211.1.1zh1.0.2zq
CWECWE-125
PublishedJun 9, 2026
Last enriched75d agov2
Tags
CVE-2026-9076
Trending Score43
Source articles9
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-45447EXP
Heap Use-After-Free in the PKCS7_verify() Function
Trending: 50
HIGHCVE-2026-7383EXP
Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion
Trending: 43
CRITICALCVE-2026-34182EXP
CMS AuthEnvelopedData Processing May Accept Forged Messages
Trending: 41
HIGHCVE-2026-14456
Unbounded Memory Growth in QUIC Server Incoming Channel Queue
Trending: 38
HIGHCVE-2026-34180EXP
Heap Buffer Over-read in ASN.1 Content Parsing
Trending: 38

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: affectedVersions, severity, activelyExploited, tags
Jun 9, 2026
Actively Exploited
Jun 10, 2026
Patch Available
Jun 10, 2026

Version History

v2
Last enriched 75d ago
v2Tier C75d ago

Updated affected versions, changed severity to HIGH, marked as actively exploited, and added CVE-2026-9076 tag.

affectedVersionsseverityactivelyExploitedtags
via VulDB
v175d ago

Initial creation