{"id":"UBUNTU-CVE-2026-63073","details":"Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender. CWE: CWE-134 (Use of Externally-Controlled Format String) Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses. Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.","modified":"2026-09-16T14:01:51.554292734Z","published":"2026-08-25T00:00:00Z","related":["USN-8678-1"],"upstream":["CVE-2026-63073"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-63073"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-63073"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8678-1"}],"affected":[{"package":{"name":"nodejs","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/nodejs?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.10.25~dfsg2-2ubuntu1","4.2.2~dfsg-1","4.2.3~dfsg-1","4.2.4~dfsg-1ubuntu1","4.2.4~dfsg-2","4.2.6~dfsg-1ubuntu1","4.2.6~dfsg-1ubuntu4","4.2.6~dfsg-1ubuntu4.1","4.2.6~dfsg-1ubuntu4.2","4.2.6~dfsg-1ubuntu4.2+esm1","4.2.6~dfsg-1ubuntu4.2+esm2","4.2.6~dfsg-1ubuntu4.2+esm3"],"ecosystem_specific":{"priority_reason":"OpenSSL developers have rated this low severity","binaries":[{"binary_name":"nodejs","binary_version":"4.2.6~dfsg-1ubuntu4.2+esm3"},{"binary_version":"4.2.6~dfsg-1ubuntu4.2+esm3","binary_name":"nodejs-legacy"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63073.json"}},{"package":{"name":"nodejs","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/nodejs?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.11.4~dfsg-1ubuntu1","6.11.4~dfsg-1ubuntu2","6.12.0~dfsg-1ubuntu1","6.12.0~dfsg-2ubuntu1","6.12.0~dfsg-2ubuntu2","8.10.0~dfsg-2","8.10.0~dfsg-2ubuntu0.2","8.10.0~dfsg-2ubuntu0.3","8.10.0~dfsg-2ubuntu0.4","8.10.0~dfsg-2ubuntu0.4+esm1","8.10.0~dfsg-2ubuntu0.4+esm2","8.10.0~dfsg-2ubuntu0.4+esm3","8.10.0~dfsg-2ubuntu0.4+esm4","8.10.0~dfsg-2ubuntu0.4+esm5","8.10.0~dfsg-2ubuntu0.4+esm6"],"ecosystem_specific":{"binaries":[{"binary_version":"8.10.0~dfsg-2ubuntu0.4+esm6","binary_name":"nodejs"}],"priority_reason":"OpenSSL developers have rated this low severity"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63073.json"}},{"package":{"name":"edk2","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/edk2?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2025.02-8ubuntu3","2025.11-3ubuntu6","2025.11-3ubuntu7","2025.11-3ubuntu7.2"],"ecosystem_specific":{"binaries":[{"binary_name":"efi-shell-aa64","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"efi-shell-loongarch64","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"efi-shell-riscv64","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"efi-shell-x64","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"ovmf","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"ovmf-amdsev","binary_version":"2025.11-3ubuntu7.2"},{"binary_version":"2025.11-3ubuntu7.2","binary_name":"ovmf-generic"},{"binary_name":"ovmf-inteltdx","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"ovmf-legacy","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"qemu-efi-aarch64","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"qemu-efi-loongarch64","binary_version":"2025.11-3ubuntu7.2"},{"binary_name":"qemu-efi-riscv64","binary_version":"2025.11-3ubuntu7.2"}],"priority_reason":"OpenSSL developers have rated this low severity"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63073.json"}},{"package":{"name":"edk2-hwe","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/edk2-hwe?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2025.11-3ubuntu6","2025.11-3ubuntu8","2025.11-3ubuntu8.2"],"ecosystem_specific":{"binaries":[{"binary_name":"efi-shell-aa64-hwe","binary_version":"2025.11-3ubuntu8.2"},{"binary_version":"2025.11-3ubuntu8.2","binary_name":"efi-shell-loongarch64-hwe"},{"binary_name":"efi-shell-riscv64-hwe","binary_version":"2025.11-3ubuntu8.2"},{"binary_version":"2025.11-3ubuntu8.2","binary_name":"efi-shell-x64-hwe"},{"binary_version":"2025.11-3ubuntu8.2","binary_name":"ovmf-amdsev-hwe"},{"binary_name":"ovmf-generic-hwe","binary_version":"2025.11-3ubuntu8.2"},{"binary_name":"ovmf-hwe","binary_version":"2025.11-3ubuntu8.2"},{"binary_name":"ovmf-inteltdx-hwe","binary_version":"2025.11-3ubuntu8.2"},{"binary_version":"2025.11-3ubuntu8.2","binary_name":"ovmf-legacy-hwe"},{"binary_version":"2025.11-3ubuntu8.2","binary_name":"qemu-efi-aarch64-hwe"},{"binary_name":"qemu-efi-loongarch64-hwe","binary_version":"2025.11-3ubuntu8.2"},{"binary_version":"2025.11-3ubuntu8.2","binary_name":"qemu-efi-riscv64-hwe"}],"priority_reason":"OpenSSL developers have rated this low severity"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63073.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.5-1ubuntu3.4"}]}],"versions":["3.5.3-1ubuntu2","3.5.5-1ubuntu1","3.5.5-1ubuntu3","3.5.5-1ubuntu3.2","3.5.5-1ubuntu3.3"],"ecosystem_specific":{"priority_reason":"OpenSSL developers have rated this low severity","binaries":[{"binary_name":"libssl3t64","binary_version":"3.5.5-1ubuntu3.4"},{"binary_name":"openssl","binary_version":"3.5.5-1ubuntu3.4"},{"binary_version":"3.5.5-1ubuntu3.4","binary_name":"openssl-provider-legacy"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-63073.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}]}