CVE-2026-7383 is a signed integer overflow in OpenSSL's ASN1_mbstring_copy() and ASN1_mbstring_ncopy() functions when calculating destination buffer sizes for Unicode output. BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32) sizing uses left shifts of a signed character count, while UTF8STRING sizing sums per-character byte counts in a signed integer. Inputs approaching 2^30 characters can overflow these calculations. In the worst-case UNIVERSALSTRING conversion, the calculated size wraps to zero, causing a one-byte allocation followed by writes several gigabytes beyond the allocated buffer. Exploitation requires application-specific use of the affected APIs or custom ASN.1 string types with exceptionally large attacker-controlled input. Standard OpenSSL network-protocol and X.509 certificate-processing paths do not exercise the overflow. OpenSSL FIPS modules in versions 4.0, 3.6, 3.5, 3.4, and 3.0 are unaffected because the vulnerable code is outside their module boundaries.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
83 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OpenSSL's ASN1_mbstring_copy() and ASN1_mbstring_ncopy() calculate Unicode output sizes using signed integers that can overflow with extremely large inputs. An undersized allocation followed by character copying can cause heap corruption, crashes, or potentially attacker-controlled code execution. Triggering the flaw requires application-specific API use or a custom string type and attacker-controlled input of roughly half a gigabyte or more. Standard OpenSSL network-protocol and certificate-handling paths do not exercise the overflow; the description assigns Low severity. The listed FIPS modules are unaffected. The EulerOS advisory identifies affected shim packages.
OpenSSL ASN1_mbstring_copy() and ASN1_mbstring_ncopy() can overflow signed destination-size calculations for extremely large Unicode inputs, leading to heap corruption, crashes, or possible code execution. Triggering the flaw requires direct application use or a custom registered string type with roughly half a gigabyte or more of attacker-controlled input. Ordinary OpenSSL network-protocol and certificate-handling paths do not exercise the overflow. The description rates the issue Low; the listed FIPS modules are unaffected.
OpenSSL ASN.1 Unicode conversion calculates output sizes using signed integers that can overflow for extremely large inputs, leading to undersized allocations and heap corruption. Crashes or code execution are possible in applications directly using the affected conversion APIs or custom string types with attacker-controlled input of roughly half a gigabyte or more. Standard OpenSSL network and certificate-handling paths do not exercise the overflow. FIPS modules are unaffected.
OpenSSL's ASN1_mbstring_copy() and ASN1_mbstring_ncopy() can overflow signed destination-size calculations for extremely large Unicode inputs, causing a heap buffer overflow and potentially crashes or attacker-controlled code execution. Exploitation requires direct API calls or a custom registered string type with attacker-controlled input on the order of half a gigabyte or more. Standard OpenSSL network-protocol and certificate-handling paths do not exercise the overflow, and the description assigns Low severity. The advisory identifies affected EulerOS shim packages.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.