{"id":"USN-8847-2","summary":"openssl, openssl1.0 vulnerabilities","details":"USN-8847-1 fixed vulnerabilities in OpenSSL. This update provides the\ncorresponding fix for OpenSSL on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,\nUbuntu 18.04 LTS and Ubuntu 20.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that OpenSSL incorrectly handled certain certificate\n revocation list distribution point names. An attacker could possibly use\n this issue to cause OpenSSL to consume excessive memory, resulting in a\n denial of service. (CVE-2026-35189)\n\n It was discovered that OpenSSL incorrectly implemented scalar\n multiplication for non-NIST elliptic curves. An attacker could possibly use\n this issue to perform a timing side-channel attack and obtain\n sensitive information. This issue only affected Ubuntu 18.04 LTS and\n Ubuntu 20.04 LTS. (CVE-2026-54872)\n\n It was discovered that OpenSSL incorrectly implemented SM2 signature\n generation. An attacker could possibly use this issue to perform a\n timing side-channel attack and obtain sensitive information. This issue\n only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-77696)\n\n It was discovered that OpenSSL incorrectly handled DTLS retransmission\n of handshake messages. An attacker could possibly use this issue to\n cause incorrect handshake behavior or a denial of service.\n (CVE-2026-84782)","modified":"2026-10-01T00:18:16.987441165Z","published":"2026-09-29T23:28:05Z","related":["UBUNTU-CVE-2026-35189","UBUNTU-CVE-2026-54872","UBUNTU-CVE-2026-77696","UBUNTU-CVE-2026-84782"],"upstream":["CVE-2026-35189","CVE-2026-54872","CVE-2026-77696","CVE-2026-84782","UBUNTU-CVE-2026-35189","UBUNTU-CVE-2026-54872","UBUNTU-CVE-2026-77696","UBUNTU-CVE-2026-84782"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8847-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-35189"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-54872"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-77696"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-84782"}],"affected":[{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1f-1ubuntu2.27+esm17"}]}],"versions":["1.0.1e-3ubuntu1","1.0.1e-4ubuntu1","1.0.1e-4ubuntu2","1.0.1e-4ubuntu3","1.0.1e-4ubuntu4","1.0.1f-1ubuntu1","1.0.1f-1ubuntu2","1.0.1f-1ubuntu2.1","1.0.1f-1ubuntu2.2","1.0.1f-1ubuntu2.3","1.0.1f-1ubuntu2.4","1.0.1f-1ubuntu2.5","1.0.1f-1ubuntu2.7","1.0.1f-1ubuntu2.8","1.0.1f-1ubuntu2.11","1.0.1f-1ubuntu2.12","1.0.1f-1ubuntu2.15","1.0.1f-1ubuntu2.16","1.0.1f-1ubuntu2.17","1.0.1f-1ubuntu2.18","1.0.1f-1ubuntu2.19","1.0.1f-1ubuntu2.20","1.0.1f-1ubuntu2.21","1.0.1f-1ubuntu2.22","1.0.1f-1ubuntu2.23","1.0.1f-1ubuntu2.24","1.0.1f-1ubuntu2.25","1.0.1f-1ubuntu2.26","1.0.1f-1ubuntu2.27","1.0.1f-1ubuntu2.27+esm1","1.0.1f-1ubuntu2.27+esm2","1.0.1f-1ubuntu2.27+esm3","1.0.1f-1ubuntu2.27+esm4","1.0.1f-1ubuntu2.27+esm5","1.0.1f-1ubuntu2.27+esm6","1.0.1f-1ubuntu2.27+esm7","1.0.1f-1ubuntu2.27+esm9","1.0.1f-1ubuntu2.27+esm10","1.0.1f-1ubuntu2.27+esm11","1.0.1f-1ubuntu2.27+esm12","1.0.1f-1ubuntu2.27+esm13","1.0.1f-1ubuntu2.27+esm14","1.0.1f-1ubuntu2.27+esm16"],"ecosystem_specific":{"binaries":[{"binary_version":"1.0.1f-1ubuntu2.27+esm17","binary_name":"libssl1.0.0"},{"binary_version":"1.0.1f-1ubuntu2.27+esm17","binary_name":"openssl"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:14.04:LTS","cves":[{"id":"CVE-2026-35189","severity":[{"type":"Ubuntu","score":"low"}]},{"id":"CVE-2026-54872","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-77696"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"score":"high","type":"Ubuntu"}],"id":"CVE-2026-84782"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8847-2.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.2g-1ubuntu4.20+esm19"}]}],"versions":["1.0.2d-0ubuntu1","1.0.2d-0ubuntu2","1.0.2e-1ubuntu1","1.0.2f-2ubuntu1","1.0.2g-1ubuntu2","1.0.2g-1ubuntu3","1.0.2g-1ubuntu4","1.0.2g-1ubuntu4.1","1.0.2g-1ubuntu4.2","1.0.2g-1ubuntu4.4","1.0.2g-1ubuntu4.5","1.0.2g-1ubuntu4.6","1.0.2g-1ubuntu4.8","1.0.2g-1ubuntu4.9","1.0.2g-1ubuntu4.10","1.0.2g-1ubuntu4.11","1.0.2g-1ubuntu4.12","1.0.2g-1ubuntu4.13","1.0.2g-1ubuntu4.14","1.0.2g-1ubuntu4.15","1.0.2g-1ubuntu4.16","1.0.2g-1ubuntu4.17","1.0.2g-1ubuntu4.18","1.0.2g-1ubuntu4.19","1.0.2g-1ubuntu4.20","1.0.2g-1ubuntu4.20+esm1","1.0.2g-1ubuntu4.20+esm2","1.0.2g-1ubuntu4.20+esm3","1.0.2g-1ubuntu4.20+esm4","1.0.2g-1ubuntu4.20+esm5","1.0.2g-1ubuntu4.20+esm6","1.0.2g-1ubuntu4.20+esm7","1.0.2g-1ubuntu4.20+esm9","1.0.2g-1ubuntu4.20+esm10","1.0.2g-1ubuntu4.20+esm11","1.0.2g-1ubuntu4.20+esm12","1.0.2g-1ubuntu4.20+esm13","1.0.2g-1ubuntu4.20+esm14","1.0.2g-1ubuntu4.20+esm15","1.0.2g-1ubuntu4.20+esm16","1.0.2g-1ubuntu4.20+esm18"],"ecosystem_specific":{"binaries":[{"binary_name":"libssl1.0.0","binary_version":"1.0.2g-1ubuntu4.20+esm19"},{"binary_name":"openssl","binary_version":"1.0.2g-1ubuntu4.20+esm19"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8847-2.json","cves_map":{"cves":[{"id":"CVE-2026-35189","severity":[{"type":"Ubuntu","score":"low"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-54872"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2026-77696"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2026-84782"}],"ecosystem":"Ubuntu:Pro:16.04:LTS"}}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.1~18.04.23+esm11"}]}],"versions":["1.0.2g-1ubuntu13","1.0.2g-1ubuntu14","1.0.2n-1ubuntu1","1.1.0g-2ubuntu1","1.1.0g-2ubuntu2","1.1.0g-2ubuntu3","1.1.0g-2ubuntu4","1.1.0g-2ubuntu4.1","1.1.0g-2ubuntu4.3","1.1.1-1ubuntu2.1~18.04.1","1.1.1-1ubuntu2.1~18.04.2","1.1.1-1ubuntu2.1~18.04.3","1.1.1-1ubuntu2.1~18.04.4","1.1.1-1ubuntu2.1~18.04.5","1.1.1-1ubuntu2.1~18.04.6","1.1.1-1ubuntu2.1~18.04.7","1.1.1-1ubuntu2.1~18.04.8","1.1.1-1ubuntu2.1~18.04.9","1.1.1-1ubuntu2.1~18.04.10","1.1.1-1ubuntu2.1~18.04.13","1.1.1-1ubuntu2.1~18.04.14","1.1.1-1ubuntu2.1~18.04.15","1.1.1-1ubuntu2.1~18.04.17","1.1.1-1ubuntu2.1~18.04.19","1.1.1-1ubuntu2.1~18.04.20","1.1.1-1ubuntu2.1~18.04.21","1.1.1-1ubuntu2.1~18.04.22","1.1.1-1ubuntu2.1~18.04.23","1.1.1-1ubuntu2.1~18.04.23+esm1","1.1.1-1ubuntu2.1~18.04.23+esm3","1.1.1-1ubuntu2.1~18.04.23+esm4","1.1.1-1ubuntu2.1~18.04.23+esm5","1.1.1-1ubuntu2.1~18.04.23+esm6","1.1.1-1ubuntu2.1~18.04.23+esm7","1.1.1-1ubuntu2.1~18.04.23+esm8","1.1.1-1ubuntu2.1~18.04.23+esm9","1.1.1-1ubuntu2.1~18.04.23+esm10"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"libssl1.1","binary_version":"1.1.1-1ubuntu2.1~18.04.23+esm11"},{"binary_name":"openssl","binary_version":"1.1.1-1ubuntu2.1~18.04.23+esm11"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-35189"},{"id":"CVE-2026-54872","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"score":"low","type":"Ubuntu"}]},{"id":"CVE-2026-77696","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2026-84782"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8847-2.json"}},{"package":{"name":"openssl1.0","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/openssl1.0?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.2n-1ubuntu5.13+esm7"}]}],"versions":["1.0.2n-1ubuntu2","1.0.2n-1ubuntu3","1.0.2n-1ubuntu4","1.0.2n-1ubuntu5","1.0.2n-1ubuntu5.1","1.0.2n-1ubuntu5.2","1.0.2n-1ubuntu5.3","1.0.2n-1ubuntu5.4","1.0.2n-1ubuntu5.5","1.0.2n-1ubuntu5.6","1.0.2n-1ubuntu5.7","1.0.2n-1ubuntu5.8","1.0.2n-1ubuntu5.9","1.0.2n-1ubuntu5.10","1.0.2n-1ubuntu5.11","1.0.2n-1ubuntu5.12","1.0.2n-1ubuntu5.13","1.0.2n-1ubuntu5.13+esm1","1.0.2n-1ubuntu5.13+esm2","1.0.2n-1ubuntu5.13+esm3","1.0.2n-1ubuntu5.13+esm4","1.0.2n-1ubuntu5.13+esm5","1.0.2n-1ubuntu5.13+esm6"],"ecosystem_specific":{"binaries":[{"binary_name":"libssl1.0.0","binary_version":"1.0.2n-1ubuntu5.13+esm7"},{"binary_name":"openssl1.0","binary_version":"1.0.2n-1ubuntu5.13+esm7"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-35189"},{"id":"CVE-2026-54872","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-77696"},{"id":"CVE-2026-84782","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"high"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8847-2.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1f-1ubuntu2.24+esm6"}]}],"versions":["1.1.1c-1ubuntu4","1.1.1d-2ubuntu3","1.1.1d-2ubuntu6","1.1.1f-1ubuntu1","1.1.1f-1ubuntu2","1.1.1f-1ubuntu2.1","1.1.1f-1ubuntu2.2","1.1.1f-1ubuntu2.3","1.1.1f-1ubuntu2.4","1.1.1f-1ubuntu2.5","1.1.1f-1ubuntu2.8","1.1.1f-1ubuntu2.9","1.1.1f-1ubuntu2.10","1.1.1f-1ubuntu2.11","1.1.1f-1ubuntu2.12","1.1.1f-1ubuntu2.13","1.1.1f-1ubuntu2.15","1.1.1f-1ubuntu2.16","1.1.1f-1ubuntu2.17","1.1.1f-1ubuntu2.18","1.1.1f-1ubuntu2.19","1.1.1f-1ubuntu2.20","1.1.1f-1ubuntu2.21","1.1.1f-1ubuntu2.22","1.1.1f-1ubuntu2.23","1.1.1f-1ubuntu2.24","1.1.1f-1ubuntu2.24+esm1","1.1.1f-1ubuntu2.24+esm2","1.1.1f-1ubuntu2.24+esm3","1.1.1f-1ubuntu2.24+esm4","1.1.1f-1ubuntu2.24+esm5"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"libssl1.1","binary_version":"1.1.1f-1ubuntu2.24+esm6"},{"binary_version":"1.1.1f-1ubuntu2.24+esm6","binary_name":"openssl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8847-2.json","cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"severity":[{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-35189"},{"id":"CVE-2026-54872","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"score":"low","type":"Ubuntu"}]},{"id":"CVE-2026-77696","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"low"}]},{"id":"CVE-2026-84782","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"high"}]}]}}}],"schema_version":"1.9.0"}