PT-2025-31038 · Openssl+3 · Openssl+3

Published

2023-06-20

·

Updated

2025-11-26

·

CVE-2023-53159

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions openssl crate versions prior to 0.10.55
Description The openssl crate for Rust contains an issue that allows an out-of-bounds read when an empty string is provided to X509VerifyParamRef::set host.
Recommendations Upgrade to version 0.10.55 or later.

Fix

Buffer Over-read

Weakness Enumeration

Related Identifiers

CVE-2023-53159
GHSA-GW89-822V-8V8G
GHSA-XCF7-RVMH-G6Q4
RUSTSEC-2023-0044
USN-7891-1

Affected Products

Debian
Linuxmint
Ubuntu
Openssl