CVE-2026-28386
OpenSSL OpenSSL, openssl
Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplet...
- CVSS
- 7.5
- EPSS
- 0.31% 23.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.08