USN-8847-2: OpenSSL vulnerabilities
USN-8847-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that OpenSSL incorrectly handled certain certificate
revocation list distribution point names. An attacker could possibly use
this issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. (CVE-2026-35189)
It was discovered that OpenSSL incorrectly implemented scalar
multiplication for non-NIST elliptic curves. An attacker could possibly use
this issue to perform a timing side-channel attack and obtain
sensitive information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2026-54872)
It was discovered that OpenSSL incorrectly implemented SM2 signature
generation. An attacker could possibly use this issue to perform a
timing side-channel attack and obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-77696)
It was discovered that OpenSSL incorrectly handled DTLS retransmission
of handshake messages. An attacker could possibly use this issue to
cause incorrect handshake behavior or a denial of service.
(CVE-2026-84782)