云虫漏洞情报

CVE-2026-81721 - openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF parameters to exhaust system memory and crash the process without authentication. - 漏洞详情

漏洞编号:CVE-2026-81721

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-81721

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-400

发布/更新时间:2026-08-27 / 2026-08-28

漏洞描述

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF parameters to exhaust system memory and crash the process without authentication.

相关链接

相关漏洞

« 返回首页