While validating the fix for CVE-2026-44662, I found that the same vulnerable output-sizing assumption remained reachable through another safe rust-openssl API: CipherCtxRef::cipher\_update\_inplace When AES Key Wrap with Padding processes an input whose length is not divisible by eight, the wrapper can allocate a buffer smaller than the output... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
I tested a rust-openssl security fix and found a missed path to attacker-controlled heap corruption - CVE-2026-45784
Reagiere als Erste:r — dein Feedback zählt!
SOCIAL SHARE CARD GENERATOR