SUSE-SU-2026:3005-1
Not scored
Security update for openssl-3
This update for openssl-3 fixes the following issues - CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). - CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350).
Exploit probability
Not scored
Published
July 15, 2026
Required by
Not available
Last source change
July 16, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2026:3005-1
View original source
This update for openssl-3 fixes the following issues - CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). - CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350).
05 / REFERENCES