Skip to content
Rota Nacional

Cyber ·

USN-8865-1: flaws in OpenSSL embedded in EDK II

Ubuntu Security advisory on four CVEs in EDK II, which uses an embedded OpenSSL library. The flaws can cause denial of service, excessive memory use or acceptance of forged messages.

Advisory USN-8865-1, published on 5 October 2026 in the Ubuntu Security feed, covers vulnerabilities in EDK II, the firmware base used in UEFI systems, with an embedded OpenSSL library. According to the text, incorrect handling of CMS key unwrapping could let an attacker cause a heap buffer overflow and denial of service (CVE-2026-63072), affecting Ubuntu 18.04, 20.04, 22.04, 24.04 and 26.04 LTS. Another flaw is in the CMP protection check (CVE-2026-63076), which can cause denial of service, affecting Ubuntu 24.04 and 26.04 LTS. Incorrect buffering of DTLS records (CVE-2026-54874) lets a remote attacker cause excessive memory use and denial of service. Finally, incorrect AEAD tag verification (CVE-2026-75803) can make the system accept forged messages, affecting Ubuntu 24.04 and 26.04 LTS. The text states that it is a machine translation of the feed content. To verify, consult the original advisory on the Ubuntu security notices page under USN-8865-1, and check the list of affected versions and published fixes.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free