{"id":"GHSA-hppc-g8h3-xhp3","summary":"rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer","details":"The FFI trampolines behind `SslContextBuilder::set_psk_client_callback`, `set_psk_server_callback`, `set_cookie_generate_cb`,  and `set_stateless_cookie_generate_cb` forwarded the user closure's returned usize directly to OpenSSL without checking it against the `&mut [u8]` that was handed to the closure. This can lead to buffer overflows and other unintended consequences.","aliases":["CVE-2026-41898"],"modified":"2026-07-17T21:13:46.310055074Z","published":"2026-04-22T21:00:57Z","database_specific":{"github_reviewed_at":"2026-04-22T21:00:57Z","nvd_published_at":"2026-04-24T18:16:29Z","cwe_ids":["CWE-126","CWE-130"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-hppc-g8h3-xhp3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41898"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/pull/2607"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/commit/1d109020d98fff2fb2e45c39a373af3dff99b24c"},{"type":"PACKAGE","url":"https://github.com/rust-openssl/rust-openssl"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.78"}],"affected":[{"package":{"name":"openssl","ecosystem":"crates.io","purl":"pkg:cargo/openssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.9.24"},{"fixed":"0.10.78"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-hppc-g8h3-xhp3/GHSA-hppc-g8h3-xhp3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"}]}