EulerOS 2.0 SP13 : openssl (EulerOS-SA-2026-2306)

high Nessus Plugin ID 320224

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the openssl packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

Issue summary: During processing of a crafted CMS EnvelopedData message_x000D_ with KeyAgreeRecipientInfo a NULL pointer dereference can happen._x000D_
_x000D_ Impact summary: Applications that process attacker-controlled CMS data may_x000D_ crash before authentication or cryptographic operations occur resulting in_x000D_ Denial of Service._x000D_
_x000D_ When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is_x000D_ processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier_x000D_ is examined without checking for its presence. This results in a NULL_x000D_ pointer dereference if the field is missing._x000D_
_x000D_ Applications and services that call CMS_decrypt() on untrusted input_x000D_ (e.g., S/MIME processing or CMS-based protocols) are vulnerable._x000D_
_x000D_ The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this_x000D_ issue, as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-28389)

Issue summary: An uncommon configuration of clients performing DANE TLSA-based_x000D_ server authentication, when paired with uncommon server DANE TLSA records, may_x000D_ result in a use-after-free and/or double-free on the client side._x000D_
_x000D_ Impact summary: A use after free can have a range of potential consequences_x000D_ such as the corruption of valid data, crashes or execution of arbitrary code._x000D_
_x000D_ However, the issue only affects clients that make use of TLSA records with both_x000D_ the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate_x000D_ usage._x000D_
_x000D_ By far the most common deployment of DANE is in SMTP MTAs for which RFC7672_x000D_ recommends that clients treat as 'unusable' any TLSA records that have the PKIX_x000D_ certificate usages. These SMTP (or other similar) clients are not vulnerable_x000D_ to this issue. Conversely, any clients that support only the PKIX usages, and_x000D_ ignore the DANE-TA(2) usage are also not vulnerable._x000D_
_x000D_ The client would also need to be communicating with a server that publishes a_x000D_ TLSA RRset with both types of TLSA records._x000D_
_x000D_ No FIPS modules are affected by this issue, the problem code is outside the_x000D_ FIPS module boundary.(CVE-2026-28387)

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension_x000D_ is processed a NULL pointer dereference might happen if the required CRL_x000D_ Number extension is missing._x000D_
_x000D_ Impact summary: A NULL pointer dereference can trigger a crash which_x000D_ leads to a Denial of Service for an application._x000D_
_x000D_ When CRL processing and delta CRL processing is enabled during X.509_x000D_ certificate verification, the delta CRL processing does not check_x000D_ whether the CRL Number extension is NULL before dereferencing it._x000D_ When a malformed delta CRL file is being processed, this parameter_x000D_ can be NULL, causing a NULL pointer dereference._x000D_
_x000D_ Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in_x000D_ the verification context, the certificate being verified to contain a_x000D_ freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and_x000D_ an attacker to provide a malformed CRL to an application that processes it._x000D_
_x000D_ The vulnerability is limited to Denial of Service and cannot be escalated to_x000D_ achieve code execution or memory disclosure. For that reason the issue was_x000D_ assessed as Low severity according to our Security Policy._x000D_
_x000D_ The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,_x000D_ as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-28388)

Issue summary: During processing of a crafted CMS EnvelopedData message_x000D_ with KeyTransportRecipientInfo a NULL pointer dereference can happen._x000D_
_x000D_ Impact summary: Applications that process attacker-controlled CMS data may_x000D_ crash before authentication or cryptographic operations occur resulting in_x000D_ Denial of Service._x000D_
_x000D_ When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with_x000D_ RSA-OAEP encryption is processed, the optional parameters field of_x000D_ RSA-OAEP SourceFunc algorithm identifier is examined without checking_x000D_ for its presence. This results in a NULL pointer dereference if the field_x000D_ is missing._x000D_
_x000D_ Applications and services that call CMS_decrypt() on untrusted input_x000D_ (e.g., S/MIME processing or CMS-based protocols) are vulnerable._x000D_
_x000D_ The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this_x000D_ issue, as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-28390)

Tenable has extracted the preceding description block directly from the EulerOS openssl security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected openssl packages.

See Also

http://www.nessus.org/u?f1044d86

Plugin Details

Severity: High

ID: 320224

File Name: EulerOS_SA-2026-2306.nasl

Version: 1.1

Type: Local

Published: 6/10/2026

Updated: 6/10/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-28387

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:huawei:euleros:openssl, p-cpe:/a:huawei:euleros:openssl-devel, p-cpe:/a:huawei:euleros:openssl-libs, p-cpe:/a:huawei:euleros:openssl-perl, p-cpe:/a:huawei:euleros:openssl-help, cpe:/o:huawei:euleros:2.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Ease: No known exploits are available

Patch Publication Date: 6/10/2026

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390

IAVA: 2026-A-0308