{"id":"DEBIAN-CVE-2026-41677","details":"rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.","modified":"2026-09-01T16:06:42.017060921Z","published":"2026-04-24T18:16:29.270Z","upstream":["CVE-2026-41677"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-41677"}],"affected":[{"package":{"name":"rust-openssl","ecosystem":"Debian:12","purl":"pkg:deb/debian/rust-openssl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.10.45-1","0.10.57-1","0.10.64-1","0.10.68-1","0.10.70-1","0.10.72-1","0.10.73-1","0.10.78-1","0.10.79-1","0.10.81-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41677.json"}},{"package":{"name":"rust-openssl","ecosystem":"Debian:13","purl":"pkg:deb/debian/rust-openssl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.10.72-1","0.10.73-1","0.10.78-1","0.10.79-1","0.10.81-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41677.json"}},{"package":{"name":"rust-openssl","ecosystem":"Debian:14","purl":"pkg:deb/debian/rust-openssl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.78-1"}]}],"versions":["0.10.72-1","0.10.73-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41677.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}