Echo: openssl: security update to 3.5.7-1~deb13u2

high Tenable Cloud Security Plugin ID 460406

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg
parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can
contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary:
A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-
protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a
Denial of Service. CWE: CWE-476: NULL Pointer Dereference Description: When verifying the password-based
MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with
X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to
an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The
parameter type returned by X509_ALGOR_get0() was never consulted. This happens during protection
verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only
precondition is that PBM verification is reachable. On the server side this is reached from
OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected
messages, and on the client side from CMP response validation against a malicious or on-path (MITM)
server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled
memory write, and no path to code execution. CMP is a specialized feature that an application must
explicitly enable. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules
are affected by this CVE. (CVE-2026-63076)

Solution

Update the openssl library and its related packages to version 3.5.7-1~deb13u2 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-63076

Plugin Details

Severity: High

ID: 460406

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-63076

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/26/2026

Vulnerability Publication Date: 8/5/2026

Reference Information

CVE: CVE-2026-63076

IAVA: 2026-A-0878-S