PT-2026-47843 · Openssl+4 · Openssl+4

·

CVE-2026-45446

·

Published

2026-06-09

·

Updated

2026-06-26

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 3.0 through 3.3
Description The implementations of AES-SIV and AES-GCM-SIV mishandle the authentication of Additional Authenticated Data (AAD) when the ciphertext is empty, which allows for the forgery of such messages. In the provider implementation of these ciphers, the expected tag is only computed when the decryption function is invoked with non-empty data. If a caller provides AAD and then calls the EVP DecryptFinal ex() function without updating the ciphertext (which occurs when the received ciphertext length is zero), the tag is not recalculated and retains an all-zeros value. Consequently, for AES-GCM-SIV, an attacker can pass authentication using arbitrary AAD, an empty ciphertext, and an all-zeros tag without knowing the key. For AES-SIV, the attack requires the application to reuse the decryption context without resetting the key.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25237
ALSA-2026:25239
CVE-2026-45446
OPENSUSE-SU-2026:11023-1
OPENSUSE-SU-2026:21005-1
RHSA-2026:25237
RHSA-2026:25239
SUSE-SU-2026:22100-1
SUSE-SU-2026:22132-1
SUSE-SU-2026:22251-1
SUSE-SU-2026:22315-1
SUSE-SU-2026:2393-1
SUSE-SU-2026:2397-1
SUSE-SU-2026:2598-1
SUSE-SU-2026:2648-1
USN-8414-1

Affected Products

Freebsd
Linuxmint
Openssl
Rocky Linux
Ubuntu