Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized…
openssl·CWE-754·Published 2026-04-07
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext. As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue. The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext. As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue. The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.
Resumen del problema: Las aplicaciones que utilizan la encapsulación de clave RSASVE para establecer una clave de cifrado secreta pueden enviar el contenido de un búfer de memoria no inicializado a un par malicioso. Resumen del impacto: El búfer no inicializado podría contener datos sensibles de la ejecución anterior del proceso de la aplicación, lo que lleva a la fuga de datos sensibles a un atacante. RSA_public_encrypt() devuelve el número de bytes escritos en caso de éxito y -1 en caso de error. El código afectado solo prueba si el valor de retorno no es cero. Como resultado, si el cifrado RSA falla, la encapsulación aún puede devolver éxito al llamador, establecer las longitudes de salida y dejar que el llamador use el contenido del búfer de texto cifrado como si se hubiera producido un texto cifrado KEM válido. Si las aplicaciones usan EVP_PKEY_encapsulate() con RSA/RSASVE en una clave pública RSA inválida proporcionada por un atacante sin validar primero esa clave, entonces esto puede causar que el contenido obsoleto o no inicializado del búfer de texto cifrado proporcionado por el llamador sea divulgado al atacante en lugar del texto cifrado KEM. Como solución alternativa, llamar a EVP_PKEY_public_check() o EVP_PKEY_public_check_quick() antes de EVP_PKEY_encapsulate() mitigará el problema. Los módulos FIPS en 3.6, 3.5, 3.4, 3.3, 3.1 y 3.0 se ven afectados por este problema.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 3.1 | Primary | cve.org | 7.5 | — | — | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | Primary | cve.org | 7.5 | — | — | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | Secondary | NVD | 7.5 | 3.9 | 3.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |