CVE-2026-41898

Public on 2026-04-24
Modified on 2026-05-14
Description
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra aws-nitro-enclaves-cli Pending Fix
Amazon Linux 2023 aws-nitro-enclaves-cli Pending Fix
Amazon Linux 2023 aws-nitro-tpm-tools Not Affected
Amazon Linux 2 - Core clamav1.4 Not Affected
Amazon Linux 2023 clamav1.4 Not Affected
Amazon Linux 2023 clamav1.5 Pending Fix
Amazon Linux 2 - Firefox Extra firefox Not Affected
Amazon Linux 2023 firefox Not Affected
Amazon Linux 2 - Core gjs Not Affected
Amazon Linux 2023 gjs Not Affected
Amazon Linux 2023 mount-s3 Not Affected
Amazon Linux 2023 papers Not Affected
Amazon Linux 2 - Core polkit Not Affected
Amazon Linux 2023 polkit Not Affected
Amazon Linux 2 - Core rust Pending Fix
Amazon Linux 2023 rust Pending Fix
Amazon Linux 2 - Core thunderbird Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
NVD CVSSv3 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H