suse · CVE-2016-7798

Quick triage

Priority: medium Published: 2021-05-30 13:46:07 UTC Updated: 2026-04-18 16:00:20 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-7798 severity moderate: SUSE including 15 source package names (libruby2_1-2_1-2.1.9-19.3.2, ruby, …), 145 product×package rows across 48 product lines (HPE Helion OpenStack 8, Image SLES12-SP5-Azure-BYOS, … (48 product lines)): Fixed 125, Known Not Affected 20.

Description:

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

cvelogic Threat Intelligence