|
|
Log in / Subscribe / Register

Debian alert DLA-4683-1 (wolfssl)

From:  Utkarsh Gupta <utkarsh@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4683-1] wolfssl security update
Date:  Wed, 15 Jul 2026 06:27:40 +0530
Message-ID:  <CAPP0f95kChT=GXJ_xbu2FKwwL+Q4miEsVCsBrkffrW+bW=190w@mail.gmail.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-4683-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta July 15, 2026 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : wolfssl Version : 5.5.4-2+deb12u3 CVE ID : CVE-2026-5194 CVE-2026-6092 CVE-2026-6094 CVE-2026-6325 CVE-2026-6329 CVE-2026-6331 CVE-2026-6450 CVE-2026-6678 CVE-2026-6681 CVE-2026-6731 CVE-2026-7511 CVE-2026-55961 CVE-2026-55962 CVE-2026-55967 Multiple vulnerabilities were discovered in wolfSSL, a lightweight, portable, C-language-based SSL/TLS library, which could result in signature forgery, authentication bypass, information disclosure, or denial of service. CVE-2026-5194 Missing hash/digest size and OID checks allowed digests smaller than appropriate for the relevant key type to be accepted during ECDSA certificate signature verification, weakening ECDSA certificate-based authentication when EdDSA or ML-DSA support was also enabled. CVE-2026-6092 When configured with HAVE_ENCRYPT_THEN_MAC, the TLS resumption path could fall back to MAC-then-Encrypt instead of enforcing Encrypt-then-MAC. CVE-2026-6094 A heap buffer over-read in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS#7 EnvelopedData could be triggered by attacker-supplied data delivered via S/MIME or CMS. CVE-2026-6325 An out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list allowed a write past the bounds of the destination buffer. CVE-2026-6329 PKCS#12 MAC verification compared the computed HMAC against the stored MAC using an attacker-controlled length, allowing a truncated or zero-length MAC to be accepted and defeating the integrity protection of the MAC. CVE-2026-6331 An HMAC zero-length tag forgery in EVP_DigestVerifyFinal allowed a truncated or empty tag to be accepted as a valid signature, because the supplied length was only checked not to exceed the MAC length. CVE-2026-6450 A CRL critical extension bypass in ParseCRL_Extensions allowed a crafted CRL carrying an unhandled critical extension to be accepted. This only affects builds with CRL support enabled. CVE-2026-6678 An integer underflow in wc_PKCS7_DecryptOri when handling crafted OtherRecipientInfo led to incorrect length handling during decryption. CVE-2026-6681 The PKCS#7 decode path ignored the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. CVE-2026-6731 An X.509 name constraint bypass allowed a certificate whose Subject Common Name violated an issuing CA's DNS name constraints to be accepted when the CN was treated as a DNS-type name. CVE-2026-7511 A PKCS7_verify signer confusion issue meant the signer associated with a signature was not correctly bound, permitting a forged signature to be accepted. CVE-2026-55961 wolfSSL_PKCS7_verify() returned success for a degenerate (certs-only) PKCS#7 object containing no signer, so a bundle carrying no valid signature could be reported as verified. This only affects OpenSSL compatibility builds. CVE-2026-55962 A TLS 1.3 post-handshake authentication issue allowed a server to accept a client's Finished message without the client having sent a Certificate and CertificateVerify. This only affects TLS 1.3 servers configured with and actively using post-handshake authentication. CVE-2026-55967 AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse and consequent plaintext recovery. For Debian 12 bookworm, these problems have been fixed in version 5.5.4-2+deb12u3. We recommend that you upgrade your wolfssl packages. For the detailed security status of wolfssl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/wolfssl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmpW2t8ACgkQgj6WdgbD S5Yd/w//cRLPPvkN27oVu2lChqWbBmLX1NlHTtAvRM7TYz8O/BMc7d1wNobu9gG6 ydWa6jMckU4WjajhxBvPwsoUkRKru1vdrCfcv/Zwazj50iFb/mXtsXg6DcmzyRLn dRguFqP1nSAxifZIJPEschNTajaNSkhFiiUTQb8GlaHILkveia8c0NByAVZaL709 REsWq1BEXTW8s/jN0o3CNdO95Av/YogVJEoGAF51YOcU4GZNoGWWIF/U8UGgeJlJ Cia0AsoGOxO9u8gOlxALdFZorWTF/Tys4NzkvcoQOoYnANevK0a1DPMZ+rR4MtUh lIJyPhtsceeKG/TSTAwPI5dwu5OaiuojRUjLhF2gtDKN4ylBYFUaQn9qvn964AfM otxA9CfGYzT6fDrtXtYBiUG214RAZLU0bKQc8PGWLAXbnZSUKHkHcdCMNA11e61R Q7u3Clc+zhBmJJvITWFZbbE8imw/YWLgo8vwCGhfH53nUNfd0XHXs9F+F76IsPAy Pf4VH2JgbBxu6g5+Hobhpwq1bkqcPeMrB1MwBZBh1Pop6ZtQ20RraTCliidGpqb+ gjEeKgwIuwmYzJpcy89XMG76TRH6OVl1yWgNrjjKABsBGoSoy+cXjBRu8FwGarv+ i07yNP8R/rY+d8rf/0QUtSzghsHmCOKsuncY/bj8EvGXLiJTfYo= =ddmq -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds