Executive brief
OpenSSL is a widely used security library that helps protect data sent over the internet. A flaw in how it handles certain encryption keys could allow an attacker to trick a server into sending back pieces of its own memory instead of encrypted data. This could lead to the exposure of sensitive information, such as passwords or private keys, from the server's previous operations.
Technical details
A vulnerability exists in OpenSSL's RSASVE key encapsulation mechanism (KEM) where the `RSA_public_encrypt()` return value is incorrectly validated. The function returns the number of bytes written on success and -1 on failure, but the affected code only checked if the return value was non-zero. If an attacker provides an invalid RSA public key that causes encryption to fail, the `EVP_PKEY_encapsulate()` function may still report success while leaving the ciphertext buffer populated with uninitialized or stale memory contents. This leads to information disclosure of sensitive data from the application process. The issue affects OpenSSL versions 3.0 through 3.6 and has been patched in versions 3.6.2, 3.5.6, 3.4.5, and 3.3.7.
Affected products
- OpenSSL OpenSSL 3.6.0 to 3.6.1, 3.5.0 to 3.5.5, 3.4.0 to 3.4.4, 3.3.0 to 3.3.6, 3.1.0 to 3.1.7, 3.0.0 to 3.0.15
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2026-04-06: patched: Fixes committed to OpenSSL repository
- 2026-04-07: advisory: OpenSSL Security Advisory published
- 2026-04-07: disclosed
References
- https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac
- https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482
- https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406
- https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790
- https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e
- https://openssl-library.org/news/secadv/20260407.txt
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html