Echo: openssl: security update to 3.5.7-1~deb13u3

high Tenable Self-Hosted Container Security Plugin ID 463458

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is
suspended part-way through. The retransmitted message can be read past the message buffer and the
retransmission overwrites the internal state the suspended write needs to resume correctly. Impact
summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or
cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-
of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write
can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more
data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the
retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.
The retransmission logic reused the same internal buffer and position tracking as the message that was
still being written, without resetting the position back to the start of the message being retransmitted.
As a result the retransmission was read starting from wherever the suspended write had left off, producing
a mislabelled message whose body was leftover bytes from the other, larger message still in flight -
content that was never meant to be sent at that point, and which could run past the end of the allocated
buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion
while another write is suspended overwrites the same shared bookkeeping that the suspended write depends
on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(),
SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with
the message and aborts the process in a debugging build. The fix resets the retransmission's read position
to the start of the message before resending, and skips retransmission entirely whenever a handshake write
is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code
is outside the FIPS module boundary. (CVE-2026-84782)

Solution

Update the openssl library and its related packages to version 3.5.7-1~deb13u3 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-84782

Plugin Details

Severity: High

ID: 463458

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.3

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:C

CVSS Score Source: CVE-2026-84782

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-84782

IAVA: 2026-A-1072