CVE-2026-28386Disclosure(openssl / openssl)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected. OpenSSL FIPS module in 3.6 version is affected by this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-07: 2Mentions · 2026-04-08: 3Mentions · 2026-04-12: 1Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-07: 2Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-12: 1Technical Details · 2026-04-21: 104-0704-0804-1204-21
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-083
Disclosure1General1Patch1
2026-04-121
General1
2026-04-211
Disclosure1
Full discourse7 posts
  • Wazuh@wazuh
    Disclosure

    OpenSSL is affected by CVE-2026-28386 (CVSS 9.1), an out-of-bounds read flaw in AES-CFB-128 on AVX-512 systems with VAES support that may cause application crashes (DoS). The issue is fixed in OpenSSL 3.6 and later. Read on: https://cti.wazuh.com/vulnerabilities/cves/CVE-2026-28386 #Vulnerability #Cybersecurity https://t.co/vNumK4iWWC

    Post summary

    OpenSSL CVE-2026-28386 is an out-of-bounds read flaw that can cause DoS on AVX-512 systems, fixed in OpenSSL 3.6+.

    090133613
    8.1K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    OpenSSLの脆弱性(Moderate: CVE-2026-31790, Low: CVE-2026-28386〜CVE-2026-28390, CVE-2026-31789)と3.6.2, 3.5.6, 3.4.5, 3.3.7, 3.0.20, 1.1.1zg, 1.0.2zpリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssl #openssl https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260408/

    Post summary

    The tweet announces several moderate and low severity OpenSSL CVEs and indicates that patched releases are available, serving as a disclosure of the vulnerability and its remedy.

    00020185
    370 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28386 Out-of-Bounds Read in OpenSSL FIPS Module 3.6 AES-CFB128 on AVX-512 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28386

    Post summary

    The post briefly references CVE-2026-28386, describing it as an out-of-bounds read in the OpenSSL FIPS module AES-CFB128 on AVX-512, and provides a link to a vulnerability details page.

    0000170
    4.0K followersView on X
  • ますだまさる@m_masaru
    General

    SSLの観点で見ていくと https://nvd.nist.gov/vuln/detail/CVE-2026-28386 CVE-2026-31790 RSA KEMはSSLで使用しないので影響なし CVE-2026-28386 CFBモードはSSLで使用しないので影響なし CVE-2026-28387 DONEはDNSSECベースの証明書検証の仕組みだけどSSL実装レイヤで対応はないので影響なし CVE-2026-28388 delta CRLは、ブラウザは独自にCRLをチェックしているしブラウザ以外は基本CRLをチェックしていないのでSSLに影響なし。SSLでのVPNとかに限定するとあるかも CVE-2026-28389 CMSはSSLで使用していないので影響なし CVE-2026-28390 CMSは同上 CVE-2026-31789 32bit環境で1GiBを超えるOCTET STRINGを含んだ証明書をロードすると発生するのだけど、SSL handshakeのserver cerfificatesのlengthが24bitでmax 16MiBなのでSSLには影響なし

    Post summary

    The post lists several CVEs and explains why they do not affect SSL, with no mention of PoCs, exploits, or patches.

    00000188
    149 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in OpenSSL 3.6.x (eight CVEs: RSA KEM, AES-CFB-128, DANE, CMS, delta CRL, hex conversion) 📅 **Timeline:** Disclosure: 2026-03-13, Patch: 2026-04-07 🆔 **CVE-2026-31790** 🆔 **CVE-2026-2673** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 13.657% 🆔 **CVE-2026-28386** 🆔 **CVE-2026-28387** 🆔 **CVE-2026-28388** 🆔 **CVE-2026-28389** 🆔 **CVE-2026-28390** 🆔 **CVE-2026-31789** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** OpenSSL 3.6.x, OpenSSL 3.5.x 🔧 **Fixed Versions:** OpenSSL 3.6.2, OpenSSL 3.5.6 🫨 **Attack Vectors:** - Network-facing TLS/KEM operations (RSASVE) - AES-CFB-128 processing on x86-64 with AVX-512 - DANE TLSA-based client processing - Processing of attacker-controlled CRLs (delta CRL) - Processing of attacker-controlled CMS EnvelopedData (KeyAgree and KeyTransport) - Conversion/printing of large X.509 extension OCTET STRINGS (32-bit platforms) 📝 **Summary:** Multiple memory-safety and parsing bugs in OpenSSL 3.6.x (and some 3.5.x) can cause crashes (DoS), memory disclosure (notably RSA KEM and AES-CFB-128 on AVX‑512), and in constrained cases heap overflow leading to potential code execution on 32‑bit. Prioritize patching systems that perform TLS/KEM operations, process CMS/CRLs/TLSA records, or run on x86‑64 with AVX‑512. 📈 **Impact Scope:** Library-level issues in OpenSSL 3.6.x (and some 3.5.x) enabling crashes (DoS), memory disclosure (RSA KEM, AES-CFB read), and potential memory corruption or code execution (heap overflow on 32-bit); affects servers and clients that use the vulnerable APIs or process untrusted CMS/CRL/certificates. Prioritize AES-CFB-128 on x86-64 with AVX-512 due to memory-read exposure. 🛡️ **Recommended Actions:** - Upgrade affected deployments to OpenSSL 3.6.2 (or OpenSSL 3.5.6 for 3.5 users) and redeploy dependent software immediately. - Apply vendor patches and rebuild/redeploy static-linked/OpenSSL-linked binaries. - For RSASVE (CVE-2026-31790), validate RSA public keys before encapsulation (EVP_PKEY_public_check() / EVP_PKEY_public_check_quick()); avoid processing untrusted CMS/CRL/TLSA inputs where possible. 🪢 **Related Resources:** - https://github.com/openssl/openssl/releases/tag/openssl-3.6.2 - https://openssl-library.org/news/secadv/20260407.txt 🏷 **Tags:** #Cybersecurity #OpenSSL #Crypto

    Post summary

    The alert details multiple OpenSSL 3.6.x vulnerabilities, their technical vectors, affected versions, and urges immediate patching to OpenSSL 3.6.2 or 3.5.6 to mitigate DoS, memory disclosure, and potential code execution risks.

    0000041
    276 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28386 Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes whe… https://www.cve.org/CVERecord?id=CVE-2026-28386

    Post summary

    CVE-2026-28386 describes an out‑of‑bounds read vulnerability affecting AES-CFB128 encryption/decryption on AVX‑512/VAES enabled systems; no exploit, mitigation, or PoC details are provided.

    00000153
    57.0K followersView on X
  • TRONCAL Yannick@ytroncal
    Disclosure

    OpenSSL 3.6.2 Is Now Available for Download with Important Security Fixes Patches CVE-2026-31790, CVE-2026-2673, CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, and CVE-2026-31789. https://9to5linux.com/openssl-3-6-2-is-now-available-for-download-with-important-security-fixes

    Post summary

    The article announces the release of OpenSSL 3.6.2, highlighting that it includes patches for several CVEs, thereby serving as a disclosure of vendor remediation.

    0000064
    139 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more