---
schema_version: '1.0'
id: security-20260705-bae3e0
url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-34181
url_hash: bae3e0e0994244c435d44dd76e755b714b2ec8b3b154f05dcc3b508a90c25d65
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-34181
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2026-34181
- severity:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- openssl
- Debian
lang: en
published_at: '2026-06-09T17:17:04Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:36:29Z'
status: published
content_hash: ba52a12a8fdba4005e36a3ce6ffa7ed4cf92dae7f215af23eb094912f18214f5
license_note: full
summary: 'Issue Summary: The PKCS#12 file processing fails to perform sufficient input
  validation for files that use Password-Based Message Authentication Code 1 (PBMAC1)
  integrity mechanism allowing a certificate and private key forgery.  Impact Summary:
  An attacker impersonating a user c'
summary_source: rss
summary_en: 'Issue Summary: The PKCS#12 file processing fails to perform sufficient
  input validation for files that use Password-Based Message Authentication Code 1
  (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact
  Summary: An attacker impersonating a user c'
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2026-34181 — openssl
---

# DEBIAN-CVE-2026-34181 — openssl

## TL;DR
Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user c

## Key Points
- cve / DEBIAN-CVE-2026-34181 / severity:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N / openssl / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
**Advisory:** DEBIAN-CVE-2026-34181

**Affected (your watchlist):**
- `Debian:openssl` 3.0.11-1~deb12u2 → no fixed version listed [rpi]

**Details:**
Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2026-34181

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2026-34181_

## Source
元記事: [DEBIAN-CVE-2026-34181 — openssl](https://osv.dev/vulnerability/DEBIAN-CVE-2026-34181) — published 2026-06-09T17:17:04Z
