Echo: openssl: security update to 3.5.7-1~deb13u3

medium Tenable Self-Hosted Container Security Plugin ID 465428

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may
dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact
summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for
the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking
a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR
instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr
<file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via
OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of
the certificate, so the client does not send them. A server may optionally name the certificate it revoked
in its response, and the client then compares that name against what it sent. Having sent neither an
issuer name nor a serial number, it has nothing to compare against, and a server returning a specially
crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked
for valid message protection before the affected code is reached, so an attacker must be a malicious or
compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection.
Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather
than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the
CMP protocol implementation is outside the OpenSSL FIPS module boundary. (CVE-2026-75805)

Solution

Update the openssl library and its related packages to version 3.5.7-1~deb13u3 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-75805

Plugin Details

Severity: Medium

ID: 465428

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-75805

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-75805

IAVA: 2026-A-1072