CVE-2026-58102: Openssl Obj2txt Oob Read
OBJ_obj2txt returns the full required string length, not the number of bytes actually written to the buffer. If an attacker controls the input, this return value can exceed the allocated buffer size. Passing it directly as a length argument to read operations causes an out-of-bounds read. Size the buffer to the required length first, then format, and store t
greprules fetch cve-2026-58102-openssl-obj2txt-oob-read --engine opengrepDescription
OBJ_obj2txt returns the full required string length, not the number of bytes actually written to the buffer. If an attacker controls the input, this return value can exceed the allocated buffer size. Passing it directly as a length argument to read operations causes an out-of-bounds read. Size the buffer to the required length first, then format, and store t
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.