Echo: openssl: security update to 3.5.5-1~deb13u2

high Tenable Self-Hosted Container Security Plugin ID 465839

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when
paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the
client side. Impact summary: A use after free can have a range of potential consequences such as the
corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients
that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2)
certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends
that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or
other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the
PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be
communicating with a server that publishes a TLSA RRset with both types of TLSA records. No FIPS modules
are affected by this issue, the problem code is outside the FIPS module boundary. (CVE-2026-28387)

Solution

Update the openssl library and its related packages to version 3.5.5-1~deb13u2 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-28387

Plugin Details

Severity: High

ID: 465839

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.62

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-28387

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/8/2026

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2026-28387

IAVA: 2026-A-0308-S