Skip to content
Ubuntu OpenSSL Security Issues Critical Denial of Service USN-8847

Ubuntu OpenSSL Security Issues Critical Denial of Service USN-8847

Linuxsecurity •LinuxSecurity Advisories • September 29, 2026

CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×

Several security issues were fixed in OpenSSL. Software Description: - openssl: Secure Socket Layer (SSL) cryptographic library and tools Details: It was discovered that OpenSSL incorrectly handled certain certificate revocation list distribution point names. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service. (CVE-2026-35189) It was discovered that OpenSSL incorrectly handled QUIC unvalidated amplification credit accounting. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-35191) It was discovered that OpenSSL incorrectly implemented scalar multiplication for non-NIST elliptic curves. An attacker could possibly use this issue to perform a timing side-channel attack and obtain sensitive information. (CVE-2026-54872) It was discovered that OpenSSL incorrectly implemented SM2 scalar multiplication on ARM64 and RISC-V architectures. An... Read the Full Advisory

Several security issues were fixed in OpenSSL.

Software Description:

- openssl: Secure Socket Layer (SSL) cryptographic library and tools

It was discovered that OpenSSL incorrectly handled certain certificate

revocation list distribution point names. An attacker could possibly use

this issue to cause OpenSSL to consume excessive memory, resulting in a

denial of service. (CVE-2026-35189)

It was discovered that OpenSSL incorrectly handled QUIC unvalidated

amplification credit accounting. An attacker could possibly use this

issue to cause a denial of service. This issue only affected

Ubuntu 26.04 LTS. (CVE-2026-35191)

It was discovered that OpenSSL incorrectly implemented scalar

multiplication for non-NIST elliptic curves. An attacker could possibly

use this issue to perform a timing side-channel attack and obtain

sensitive information. (CVE-2026-54872)

It was discovered that OpenSSL incorrectly implemented SM2 scalar

multiplication on ARM64 and RISC-V architectures. An...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssl3t64 3.5.5-1ubuntu3.6 Ubuntu 24.04 LTS libssl3t64 3.0.13-0ubuntu3.16 Ubuntu 22.04 LTS libssl3 3.0.2-0ubuntu1.30 After a standard system update you need to reboot your computer to make all the necessary changes.

CVE-2026-35189, CVE-2026-35191, CVE-2026-54872, CVE-2026-54875,

CVE-2026-72897, CVE-2026-75804, CVE-2026-75805, CVE-2026-75806,

CVE-2026-77696, CVE-2026-84782, CVE-2026-84784

Ubuntu Security Notice USN-8847-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases