Echo: openssl: security update to 3.5.7-1~deb13u2

high Tenable Cloud Security Plugin ID 458625

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped
key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports,
causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message
can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with
CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-
bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping
allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and
change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the
unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation),
the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure. The write is a
fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special
configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap
corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the
worst case so a failed unwrap cannot write past the allocation. FIPS impact: no As the CMS code lives
outside the FIPS module boundary, no FIPS modules are affected by this CVE. (CVE-2026-63072)

Solution

Update the openssl library and its related packages to version 3.5.7-1~deb13u2 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-63072

Plugin Details

Severity: High

ID: 458625

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

Percentile: 96.11

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:C

CVSS Score Source: CVE-2026-63072

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/26/2026

Vulnerability Publication Date: 8/5/2026

Reference Information

CVE: CVE-2026-63072

IAVA: 2026-A-0878-S