Back Linuxsecurity Ubuntu OpenSSL Security Issues Critical Denial of Service USN-8847
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
Several security issues were fixed in OpenSSL. Software Description: - openssl: Secure Socket Layer (SSL) cryptographic library and tools Details: It was discovered that OpenSSL incorrectly handled certain certificate revocation list distribution point names. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. (CVE-2026-35189) It was discovered that OpenSSL incorrectly handled QUIC unvalidated amplification credit accounting. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-35191) It was discovered that OpenSSL incorrectly implemented scalar multiplication for non-NIST elliptic curves. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. (CVE-2026-54872) It was discovered that OpenSSL incorrectly implemented SM2 scalar multiplication on ARM64 and RISC-V architectures. An... Read the Full Advisory
Several security issues were fixed in OpenSSL.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
It was discovered that OpenSSL incorrectly handled certain certificate
revocation list distribution point names. An attacker could possibly use
this issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. (CVE-2026-35189)
It was discovered that OpenSSL incorrectly handled QUIC unvalidated
amplification credit accounting. An attacker could possibly use this
issue to cause a denial of service. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-35191)
It was discovered that OpenSSL incorrectly implemented scalar
multiplication for non-NIST elliptic curves. An attacker could possibly
use this issue to perform a timing side-channel attack and obtain
sensitive information. (CVE-2026-54872)
It was discovered that OpenSSL incorrectly implemented SM2 scalar
multiplication on ARM64 and RISC-V architectures. An...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssl3t64 3.5.5-1ubuntu3.6 Ubuntu 24.04 LTS libssl3t64 3.0.13-0ubuntu3.16 Ubuntu 22.04 LTS libssl3 3.0.2-0ubuntu1.30 After a standard system update you need to reboot your computer to make all the necessary changes.
CVE-2026-35189, CVE-2026-35191, CVE-2026-54872, CVE-2026-54875,
CVE-2026-72897, CVE-2026-75804, CVE-2026-75805, CVE-2026-75806,
CVE-2026-77696, CVE-2026-84782, CVE-2026-84784
Ubuntu Security Notice USN-8847-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
