USN-8678-2: OpenSSL, OpenSSL 1.0 vulnerabilities

Publication date

25 August 2026

Overview

Several security issues were fixed in OpenSSL and OpenSSL 1.0.


Packages

  • openssl - Secure Socket Layer (SSL) cryptographic library and tools
  • openssl1.0 - Secure Socket Layer (SSL) cryptographic library and tools

Details

USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.

In addition, this update also fixes the following issues that were
not previously addressed in those releases:

It was discovered that OpenSSL incorrectly handled TLS handshake
message buffering. A remote attacker could possibly use this issue to
cause OpenSSL to consume excessive memory, leading to a denial of
service. (LP: #2161371)

It was discovered that OpenSSL incorrectly handled session cache
management when processing TLSv1.3 sessions. A remote attacker could
possibly use this issue to cause OpenSSL to consume excessive memory,
leading to a denial of service. This issue only affected OpenSSL 1.1.1
on Ubuntu 18.04 LTS. (CVE-2024-2511)

It was discovered that OpenSSL incorrectly handled the...

USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.

In addition, this update also fixes the following issues that were
not previously addressed in those releases:

It was discovered that OpenSSL incorrectly handled TLS handshake
message buffering. A remote attacker could possibly use this issue to
cause OpenSSL to consume excessive memory, leading to a denial of
service. (LP: #2161371)

It was discovered that OpenSSL incorrectly handled session cache
management when processing TLSv1.3 sessions. A remote attacker could
possibly use this issue to cause OpenSSL to consume excessive memory,
leading to a denial of service. This issue only affected OpenSSL 1.1.1
on Ubuntu 18.04 LTS. (CVE-2024-2511)

It was discovered that OpenSSL incorrectly handled the SSL_select_next_proto
function when called with an empty client protocol list. A remote attacker
could possibly use this issue to cause OpenSSL to disclose private memory
contents to the peer, leading to a loss of confidentiality. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-5535)

Original advisory details:

It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)

It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
20.04 LTS focal libssl1.1 –  1.1.1f-1ubuntu2.24+esm5  
openssl –  1.1.1f-1ubuntu2.24+esm5  
18.04 LTS bionic libssl1.0.0 –  1.0.2n-1ubuntu5.13+esm6  
libssl1.1 –  1.1.1-1ubuntu2.1~18.04.23+esm10  
openssl –  1.1.1-1ubuntu2.1~18.04.23+esm10  
openssl1.0 –  1.0.2n-1ubuntu5.13+esm6  
16.04 LTS xenial libssl1.0.0 –  1.0.2g-1ubuntu4.20+esm18  
openssl –  1.0.2g-1ubuntu4.20+esm18  
14.04 LTS trusty libssl1.0.0 –  1.0.1f-1ubuntu2.27+esm16  
openssl –  1.0.1f-1ubuntu2.27+esm16  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›