EulerOS 2.0 SP15 : openssl (EulerOS-SA-2026-2497)

critical Nessus Plugin ID 323147

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the openssl packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

Issue summary: Applications using RSASVE key encapsulation to establish_x000D_ a secret encryption key can send contents of an uninitialized memory buffer to_x000D_ a malicious peer._x000D_
_x000D_ Impact summary: The uninitialized buffer might contain sensitive data from the_x000D_ previous execution of the application process which leads to sensitive data_x000D_ leakage to an attacker._x000D_
_x000D_ RSA_public_encrypt() returns the number of bytes written on success and -1_x000D_ on error. The affected code tests only whether the return value is non-zero._x000D_ As a result, if RSA encryption fails, encapsulation can still return success to_x000D_ the caller, set the output lengths, and leave the caller to use the contents of_x000D_ the ciphertext buffer as if a valid KEM ciphertext had been produced._x000D_
_x000D_ If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an_x000D_ attacker-supplied invalid RSA public key without first validating that key,_x000D_ then this may cause stale or uninitialized contents of the caller-provided_x000D_ ciphertext buffer to be disclosed to the attacker in place of the KEM_x000D_ ciphertext._x000D_
_x000D_ As a workaround calling EVP_PKEY_public_check() or_x000D_ EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate_x000D_ the issue._x000D_
_x000D_ The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.(CVE-2026-31790)

Issue summary: An uncommon configuration of clients performing DANE TLSA-based_x000D_ server authentication, when paired with uncommon server DANE TLSA records, may_x000D_ result in a use-after-free and/or double-free on the client side._x000D_
_x000D_ Impact summary: A use after free can have a range of potential consequences_x000D_ such as the corruption of valid data, crashes or execution of arbitrary code._x000D_
_x000D_ However, the issue only affects clients that make use of TLSA records with both_x000D_ the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate_x000D_ usage._x000D_
_x000D_ By far the most common deployment of DANE is in SMTP MTAs for which RFC7672_x000D_ recommends that clients treat as 'unusable' any TLSA records that have the PKIX_x000D_ certificate usages. These SMTP (or other similar) clients are not vulnerable_x000D_ to this issue. Conversely, any clients that support only the PKIX usages, and_x000D_ ignore the DANE-TA(2) usage are also not vulnerable._x000D_
_x000D_ The client would also need to be communicating with a server that publishes a_x000D_ TLSA RRset with both types of TLSA records._x000D_
_x000D_ No FIPS modules are affected by this issue, the problem code is outside the_x000D_ FIPS module boundary.(CVE-2026-28387)

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension_x000D_ is processed a NULL pointer dereference might happen if the required CRL_x000D_ Number extension is missing._x000D_
_x000D_ Impact summary: A NULL pointer dereference can trigger a crash which_x000D_ leads to a Denial of Service for an application._x000D_
_x000D_ When CRL processing and delta CRL processing is enabled during X.509_x000D_ certificate verification, the delta CRL processing does not check_x000D_ whether the CRL Number extension is NULL before dereferencing it._x000D_ When a malformed delta CRL file is being processed, this parameter_x000D_ can be NULL, causing a NULL pointer dereference._x000D_
_x000D_ Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in_x000D_ the verification context, the certificate being verified to contain a_x000D_ freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and_x000D_ an attacker to provide a malformed CRL to an application that processes it._x000D_
_x000D_ The vulnerability is limited to Denial of Service and cannot be escalated to_x000D_ achieve code execution or memory disclosure. For that reason the issue was_x000D_ assessed as Low severity according to our Security Policy._x000D_
_x000D_ The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,_x000D_ as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-28388)

Issue summary: Converting an excessively large OCTET STRING value to_x000D_ a hexadecimal string leads to a heap buffer overflow on 32 bit platforms._x000D_
_x000D_ Impact summary: A heap buffer overflow may lead to a crash or possibly_x000D_ an attacker controlled code execution or other undefined behavior._x000D_
_x000D_ If an attacker can supply a crafted X.509 certificate with an excessively_x000D_ large OCTET STRING value in extensions such as the Subject Key Identifier_x000D_ (SKID) or Authority Key Identifier (AKID) which are being converted to hex,_x000D_ the size of the buffer needed for the result is calculated as multiplication_x000D_ of the input length by 3. On 32 bit platforms, this multiplication may overflow_x000D_ resulting in the allocation of a smaller buffer and a heap buffer overflow._x000D_
_x000D_ Applications and services that print or log contents of untrusted X.509_x000D_ certificates are vulnerable to this issue. As the certificates would have_x000D_ to have sizes of over 1 Gigabyte, printing or logging such certificates_x000D_ is a fairly unlikely operation and only 32 bit platforms are affected,_x000D_ this issue was assigned Low severity._x000D_
_x000D_ The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this_x000D_ issue, as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-31789)

Issue summary: During processing of a crafted CMS EnvelopedData message_x000D_ with KeyAgreeRecipientInfo a NULL pointer dereference can happen._x000D_
_x000D_ Impact summary: Applications that process attacker-controlled CMS data may_x000D_ crash before authentication or cryptographic operations occur resulting in_x000D_ Denial of Service._x000D_
_x000D_ When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is_x000D_ processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier_x000D_ is examined without checking for its presence. This results in a NULL_x000D_ pointer dereference if the field is missing._x000D_
_x000D_ Applications and services that call CMS_decrypt() on untrusted input_x000D_ (e.g., S/MIME processing or CMS-based protocols) are vulnerable._x000D_
_x000D_ The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this_x000D_ issue, as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-28389)

Issue summary: During processing of a crafted CMS EnvelopedData message_x000D_ with KeyTransportRecipientInfo a NULL pointer dereference can happen._x000D_
_x000D_ Impact summary: Applications that process attacker-controlled CMS data may_x000D_ crash before authentication or cryptographic operations occur resulting in_x000D_ Denial of Service._x000D_
_x000D_ When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with_x000D_ RSA-OAEP encryption is processed, the optional parameters field of_x000D_ RSA-OAEP SourceFunc algorithm identifier is examined without checking_x000D_ for its presence. This results in a NULL pointer dereference if the field_x000D_ is missing._x000D_
_x000D_ Applications and services that call CMS_decrypt() on untrusted input_x000D_ (e.g., S/MIME processing or CMS-based protocols) are vulnerable._x000D_
_x000D_ The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this_x000D_ issue, as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-28390)

Tenable has extracted the preceding description block directly from the EulerOS openssl security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected openssl packages.

See Also

http://www.nessus.org/u?e8f22943

Plugin Details

Severity: Critical

ID: 323147

File Name: EulerOS_SA-2026-2497.nasl

Version: 1.1

Type: Local

Published: 6/27/2026

Updated: 6/27/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31789

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:huawei:euleros:openssl-perl, p-cpe:/a:huawei:euleros:openssl-devel, p-cpe:/a:huawei:euleros:openssl, p-cpe:/a:huawei:euleros:openssl-libs, cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:openssl-help

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Ease: No known exploits are available

Patch Publication Date: 6/26/2026

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, CVE-2026-31790