🛡️ OESA-2026-3002 — edk2

🟡 CVSS 5.0 — Medium ✅ No Known Exploit OSV
5.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

edk2 security update

EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications.

Security Fix(es):

Issue summary: A specially crafted password-encrypted CMS message

can trigger a NULL pointer dereference during CMS decryption.

Impact summary: This NULL pointer dereference leads to an application crash

and a Denial of Service.

The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as

OPTIONAL in the ASN.1 specification and may therefore be absent in specially

crafted inputs. During the password-based CMS decryption the OpenSSL

CMS implementation dereferences this field without first checking whether it

was present.

An attacker who supplies such a CMS message to an application performing

password-based CMS decryption can trigger an application crash, leading to

a Denial of Service.

Applications that process password-encrypted CMS messages may be affected.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this

issue, as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-42766)

Issue summary: An attacker-controlled CMP (Certificate Management Protocol)

server could trigger a NULL pointer dereference in a CMP client application.

Impact summary: A NULL pointer dereference causes a crash of the

application and a Denial of Service.

An attacker controlling a CMP server (or acting as a man-in-the-middle) could

craft a CMP response containing a CRMF (Certificate Request Message Format)

CertRepMessage with an EncryptedValue structure where the symmAlg field

has an algorithm OID but no parameters field. When the OpenSSL CMP client

processes this response, the NULL dereference occurs, causing a crash of

the CMP client.

Applications that process untrusted CMP/CRMF messages may be affected.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this

issue, as the affected code is outside the OpenSSL FIPS module boundary.(CVE-2026-42767)

Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to

Bleichenbacher-style attack when an attacker is able to provide the CMS or

S/MIME messages and observe the error code and/or decryption output.

Impact summary: The Bleichenbacher-style attack allows an attacker to use the

victim's vulnerable application as a way to decrypt or sign messages with the

victim's private RSA key.

The attack is possible in 2 variants.

1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without

providing the recipient certificate. In this case OpenSSL iterates over every

KeyTransRecipientInfo (KTRI) without stopping at the first success.

An attacker who authors a message with two KTRI entries — the first one

wrapping a real CEK under the victim's public key, the second with an

arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to

get a valid PKCS#1 v1.5 padding if the error code of the application is

available.

That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an

adaptive-chosen-ciphertext side channel from which the attacker decrypts any

RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under

it.

2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with

the recipient certificate, and the recipient is not found, a random

key is substituted.

An attacker who authors a message and is able to compare both error code and

the result of the decryption, can mount a Bleichenbacher oracle.

We are not aware of any applications that provide a remote attacker

an opportunity to mount an attack described in these scenarios. We consider

the existence of such application very unlikely, and for this reason this

CVE has been evaluated as Low severity.

To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the

invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described

in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit

rejection was explicitly disabled.

The implicit rejection mechanism always returns a plaintext value,

the symmetric key. This result is deterministic for the ciphertext and the

private key. The length of the decryption result can happen to match the

length of the key of the symmetric cipher that was used for the content

encryption. When a certificate is not provided, the last RecipientInfo

producing a key that looks valid will be used. It may cause getting garbage

content on decryption. As a proper way to deal with this a recipient

certificate has to be provided to identify the particular RecipientInfo for

decryption.

The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as

CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.(CVE-2026-42768)

Affected software

OESA-2026-3002 is recorded against 1 package.

  • edk2 (fixed in 202308-45.oe2403sp3)

Timeline and source

Published on 19 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.openeuler.org (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)

Details

Severity MEDIUM
CVSS Score 5.0
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-19
Updated 2026-08-12
Modified 2026-07-19
Fix URL N/A

Affected Packages

Software From version Fixed in
edk2 202308-45.oe2403sp3

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in edk2

OESA-2026-3002 is rated CVSS 5.0 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.