{"id":"GHSA-ghm9-cr32-g9qj","summary":"rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check","details":"`EVP_DigestFinal()` always writes `EVP_MD_CTX_size(ctx)` to the `out` buffer. If `out` is smaller than that, `MdCtxRef::digest_final()` writes past its end, usually corrupting the stack. This is reachable from safe Rust.","aliases":["CVE-2026-41681"],"modified":"2026-07-17T21:14:37.206199315Z","published":"2026-04-22T21:05:02Z","database_specific":{"nvd_published_at":"2026-04-24T18:16:29Z","cwe_ids":["CWE-121"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-22T21:05:02Z"},"references":[{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-ghm9-cr32-g9qj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41681"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/pull/2608"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/commit/826c3888b77add418b394770e2b2e3a72d9f92fe"},{"type":"PACKAGE","url":"https://github.com/rust-openssl/rust-openssl"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.78"}],"affected":[{"package":{"name":"openssl","ecosystem":"crates.io","purl":"pkg:cargo/openssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.10.39"},{"fixed":"0.10.78"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-ghm9-cr32-g9qj/GHSA-ghm9-cr32-g9qj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}