Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer

Moderate
alex published GHSA-hppc-g8h3-xhp3 Apr 19, 2026

Package

Codestin Search App openssl (Rust)

Affected versions

>=0.9.24

Patched versions

0.10.78

Description

The FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences.

Severity

Moderate

CVE ID

CVE-2026-41898

Weaknesses

No CWEs