Packages
- openssl - Secure Socket Layer (SSL) cryptographic library and tools
- openssl1.0 - Secure Socket Layer (SSL) cryptographic library and tools
Details
USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
In addition, this update also fixes the following issues that were
not previously addressed in those releases:
It was discovered that OpenSSL incorrectly handled TLS handshake
message buffering. A remote attacker could possibly use this issue to
cause OpenSSL to consume excessive memory, leading to a denial of
service. (LP: #2161371)
It was discovered that OpenSSL incorrectly handled session cache
management when processing TLSv1.3 sessions. A remote attacker could
possibly use this issue to cause OpenSSL to consume excessive memory,
leading to a denial of service. This issue only affected OpenSSL 1.1.1
on Ubuntu 18.04 LTS. (CVE-2024-2511)
It was discovered that OpenSSL incorrectly handled the...
USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
In addition, this update also fixes the following issues that were
not previously addressed in those releases:
It was discovered that OpenSSL incorrectly handled TLS handshake
message buffering. A remote attacker could possibly use this issue to
cause OpenSSL to consume excessive memory, leading to a denial of
service. (LP: #2161371)
It was discovered that OpenSSL incorrectly handled session cache
management when processing TLSv1.3 sessions. A remote attacker could
possibly use this issue to cause OpenSSL to consume excessive memory,
leading to a denial of service. This issue only affected OpenSSL 1.1.1
on Ubuntu 18.04 LTS. (CVE-2024-2511)
It was discovered that OpenSSL incorrectly handled the SSL_select_next_proto
function when called with an empty client protocol list. A remote attacker
could possibly use this issue to cause OpenSSL to disclose private memory
contents to the peer, leading to a loss of confidentiality. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-5535)
Original advisory details:
It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)
It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 20.04 LTS focal | libssl1.1 – 1.1.1f-1ubuntu2.24+esm5 | ||
| openssl – 1.1.1f-1ubuntu2.24+esm5 | |||
| 18.04 LTS bionic | libssl1.0.0 – 1.0.2n-1ubuntu5.13+esm6 | ||
| libssl1.1 – 1.1.1-1ubuntu2.1~18.04.23+esm10 | |||
| openssl – 1.1.1-1ubuntu2.1~18.04.23+esm10 | |||
| openssl1.0 – 1.0.2n-1ubuntu5.13+esm6 | |||
| 16.04 LTS xenial | libssl1.0.0 – 1.0.2g-1ubuntu4.20+esm18 | ||
| openssl – 1.0.2g-1ubuntu4.20+esm18 | |||
| 14.04 LTS trusty | libssl1.0.0 – 1.0.1f-1ubuntu2.27+esm16 | ||
| openssl – 1.0.1f-1ubuntu2.27+esm16 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.