CVE Vulnerabilities

CVE-2026-75803

Improper Validation of Integrity Check Value

Published: Aug 25, 2026 | Modified: Sep 11, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.

Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.

CWE: CWE-354 (Improper Validation of Integrity Check Value)

Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.

FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module.

Weakness

The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl3.0.0 (including)3.0.22 (excluding)
OpensslOpenssl3.4.0 (including)3.4.7 (excluding)
OpensslOpenssl3.5.0 (including)3.5.8 (excluding)
OpensslOpenssl3.6.0 (including)3.6.4 (excluding)
OpensslOpenssl4.0.0 (including)4.0.2 (excluding)
Red Hat Hardened ImagesRedHatchunkah-main-0.6.0-3.hum1*
Red Hat Hardened ImagesRedHatpython-cryptography-main-50.0.0-1.hum1*
Red Hat Hardened ImagesRedHatrust-bootupd-main-0.2.36-3.hum1*
Red Hat Hardened ImagesRedHatopenssl3-main-3.5.8-0.1.hum1*
Red Hat Hardened ImagesRedHatopenssl-main-3.5.8-0.1.hum1*
Red Hat Hardened ImagesRedHatruby3-3-main-3.3.10-23.6.hum1*
Red Hat Hardened ImagesRedHatruby4-0-main-4.0.6-37.3.hum1*
Red Hat Hardened ImagesRedHatruby3-4-main-3.4.10-31.7.hum1*
Edk2Ubuntunoble*
Edk2Ubunturesolute*
Edk2-hweUbunturesolute*
OpensslUbuntudevel*
OpensslUbuntufips-preview/jammy*
OpensslUbuntufips-updates/jammy*
OpensslUbuntujammy*
OpensslUbuntunoble*
OpensslUbunturesolute*
OpensslUbuntuupstream*
Openssl-fipsUbuntufips-updates/noble*

Potential Mitigations

References