CVE-2026-58102: Openssl Obj2txt Oob Read

OBJ_obj2txt returns the full required string length, not the number of bytes actually written to the buffer. If an attacker controls the input, this return value can exceed the allocated buffer size. Passing it directly as a length argument to read operations causes an out-of-bounds read. Size the buffer to the required length first, then format, and store t

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Generic
greprules fetch cve-2026-58102-openssl-obj2txt-oob-read --engine opengrep

Description

OBJ_obj2txt returns the full required string length, not the number of bytes actually written to the buffer. If an attacker controls the input, this return value can exceed the allocated buffer size. Passing it directly as a length argument to read operations causes an out-of-bounds read. Size the buffer to the required length first, then format, and store t