Chainguard: multiple libcrypto3 packages, multiple openssl packages: security update to 3.6.3-r0

medium Tenable Self-Hosted Container Security Plugin ID 472844

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL
pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash
of the application and a Denial of Service. An attacker controlling a CMP server (or acting as a man-in-
the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format)
CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no
parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs,
causing a crash of the CMP client. Applications that process untrusted CMP/CRMF messages may be affected.
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is
outside the OpenSSL FIPS module boundary. (CVE-2026-42767)

Solution

Update the libcrypto3 library and its related packages to version 3.6.3-r0 or later.

Plugin Details

Severity: Medium

ID: 472844

Version: Revision 1.1

Type: Local

Published: 10/5/2026

Updated: 10/5/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.71

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-42767

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/9/2026

Reference Information

CVE: CVE-2026-42767

IAVA: 2026-A-0589-S