« Volver al listado

CVE-2026-28386

Estado: AnalizadaAlta (7.5)—

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.

Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.

The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it).

Leer descripción completaMostrar menos

Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.

Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.

OpenSSL FIPS module in 3.6 version is affected by this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de lectura fuera de límites en OpenSSL (AV:N, PR:N, UI:N) explotable remotamente en aplicaciones que usan AES-CFB128. Causa DoS por crash al acceder a memoria no mapeada en sistemas x86-64 con AVX-512/VAES.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-28386",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-28386",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-10T20:15:21.235876Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "openssl-security@openssl.org",
      "affectedData": [
        {
          "vendor": "OpenSSL",
          "product": "OpenSSL",
          "versions": [
            {
              "status": "affected",
              "version": "3.6.0",
              "lessThan": "3.6.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-07T22:16:20.513",
  "references": [
    {
      "url": "https://github.com/openssl/openssl/commit/61f428a2fc6671ede184a19f71e6e495f0689621",
      "tags": [
        "Patch"
      ],
      "source": "openssl-security@openssl.org"
    },
    {
      "url": "https://openssl-library.org/news/secadv/20260407.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "openssl-security@openssl.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "openssl-security@openssl.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Issue summary: Applications using AES-CFB128 encryption or decryption on\nsystems with AVX-512 and VAES support can trigger an out-of-bounds read\nof up to 15 bytes when processing partial cipher blocks.\n\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not written to output.\n\nThe vulnerable code path is only reached when processing partial blocks\n(when a previous call left an incomplete block and the current call provides\nfewer bytes than needed to complete it). Additionally, the input buffer\nmust be positioned at a page boundary with the following page unmapped.\nCFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or\nChaCha20-Poly1305 instead. For these reasons the issue was assessed as\nLow severity according to our Security Policy.\n\nOnly x86-64 systems with AVX-512 and VAES instruction support are affected.\nOther architectures and systems without VAES support use different code\npaths that are not affected.\n\nOpenSSL FIPS module in 3.6 version is affected by this issue."
    },
    {
      "lang": "es",
      "value": "Resumen del problema: Las aplicaciones que usan cifrado o descifrado AES-CFB128 en sistemas con soporte para AVX-512 y VAES pueden desencadenar una lectura fuera de límites de hasta 15 bytes al procesar bloques de cifrado parciales.\n\nResumen del impacto: Esta lectura fuera de límites puede desencadenar un fallo que lleva a la denegación de servicio para una aplicación si el búfer de entrada termina en un límite de página de memoria y la página siguiente no está mapeada. No hay divulgación de información ya que los bytes leídos en exceso no se escriben en la salida.\n\nLa ruta de código vulnerable solo se alcanza al procesar bloques parciales (cuando una llamada anterior dejó un bloque incompleto y la llamada actual proporciona menos bytes de los necesarios para completarlo). Además, el búfer de entrada debe estar posicionado en un límite de página con la página siguiente sin mapear. El modo CFB no se usa en los protocolos TLS/DTLS, que usan CBC, GCM, CCM o ChaCha20-Poly1305 en su lugar. Por estas razones, el problema fue evaluado como de severidad Baja según nuestra Política de Seguridad.\n\nSolo los sistemas x86-64 con soporte para instrucciones AVX-512 y VAES están afectados. Otras arquitecturas y sistemas sin soporte VAES usan rutas de código diferentes que no están afectadas.\n\nEl módulo OpenSSL FIPS en la versión 3.6 está afectado por este problema."
    }
  ],
  "lastModified": "2026-07-24T23:10:00.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A9E621D-29D8-418A-BF37-BED333C14507",
              "versionEndExcluding": "3.6.2",
              "versionStartIncluding": "3.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "openssl-security@openssl.org"
}