Executive brief
OpenSSL's CMS (Cryptographic Message Syntax) decryption feature is used to decrypt secure messages in various applications. An attacker can craft a malicious encrypted message that causes an 8-byte buffer overflow in the decryption process, corrupting the application's memory and typically causing it to crash, resulting in service unavailability.
Technical details
This is an out-of-bounds heap write vulnerability (CWE-787) in OpenSSL's CMS key unwrap logic. The root cause is that the key-unwrap output buffer is sized based on the reported unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, resulting in an 8-byte overflow past the allocation. An attacker can modify the wire OID in a legitimate CMS message to select the padded AES-wrap variant instead of the standard variant, triggering the vulnerability. The attack requires only that the victim decrypt the crafted message via CMS_decrypt() and results in deterministic heap corruption and denial of service. The fix sizes the unwrap buffer for the worst case to prevent the overflow. FIPS modules are not affected as CMS code resides outside the FIPS module boundary.
Affected products
- OpenSSL OpenSSL <UNKNOWN>
Timeline
- 2026-08-25: disclosed