---
schema_version: '1.0'
id: security-20260705-a6be1d
url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-31790
url_hash: a6be1d2c2bd650543017dd90bfabf37717214515e36fd2828c96e587867a7d6b
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-31790
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2026-31790
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- openssl
- Debian
lang: en
published_at: '2026-04-07T22:16:21Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:36:29Z'
status: published
content_hash: 1582c27558f22158255a3ccba04f4055d13a99a1deea3cc97fe0159c9b8799b1
license_note: full
summary: 'Issue summary: Applications using RSASVE key encapsulation to establish
  a secret encryption key can send contents of an uninitialized memory buffer to a
  malicious peer.  Impact summary: The uninitialized buffer might contain sensitive
  data from the previous execution of the appli'
summary_source: rss
summary_en: 'Issue summary: Applications using RSASVE key encapsulation to establish
  a secret encryption key can send contents of an uninitialized memory buffer to a
  malicious peer.  Impact summary: The uninitialized buffer might contain sensitive
  data from the previous execution of the appli'
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2026-31790 — openssl
---

# DEBIAN-CVE-2026-31790 — openssl

## TL;DR
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the appli

## Key Points
- cve / DEBIAN-CVE-2026-31790 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N / openssl / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
**Advisory:** DEBIAN-CVE-2026-31790

**Affected (your watchlist):**
- `Debian:openssl` 3.0.11-1~deb12u2 → no fixed version listed [rpi]

**Details:**
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2026-31790

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2026-31790_

## Source
元記事: [DEBIAN-CVE-2026-31790 — openssl](https://osv.dev/vulnerability/DEBIAN-CVE-2026-31790) — published 2026-04-07T22:16:21Z
