]> git.ipfire.org Git - thirdparty/openssl.git/commit
Correct handling of AEAD-encrypted CMS with inadmissibly long IV
authorIgor Ustinov <igus68@gmail.com>
Mon, 12 Jan 2026 11:19:59 +0000 (12:19 +0100)
committerTomas Mraz <tomas@openssl.org>
Mon, 26 Jan 2026 19:34:22 +0000 (20:34 +0100)
commitce39170276daec87f55c39dad1f629b56344429e
tree549e48a1180f3fda79b48ed2fddec12e92299358
parent3250efdfe99d2d7fe4fb05231add7fba864b7653
Correct handling of AEAD-encrypted CMS with inadmissibly long IV

Fixes CVE-2025-15467

Reviewed-by: Norbert Pocs <norbertp@openssl.org>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
MergeDate: Mon Jan 26 19:34:29 2026
crypto/evp/evp_lib.c