Fedora 43 : stunnel (2026-de8630b736)

medium Nessus Plugin ID 335901

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 43 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2026-de8630b736 advisory.

```
* Security bugfixes
- CVE-2026-70368: Fixed an out-of-bounds memory access triggered by logging attacker-controlled protocol messages longer than 1,024 bytes (thanks to AISLE Research and Clemens Lang).
- CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost destination filter using alternate local-address encodings and interface-scoped IPv6 destinations (thanks to AISLE Research and Clemens Lang).
- Restricted Windows GUI/service control pipes to local clients.
* Bugfixes
- Fixed concurrent DTLS handshakes from clients sharing an IP address.
- Fixed version reporting in builds from source.
- Rejected stream-oriented protocol negotiation with the UDP transport during configuration validation.
- Fixed a TCP stream truncation (thanks to Solomon Jacobs).
- Fixed a transfer() loop (thanks to Solomon Jacobs).
- Fixed log reopening logs without a configured log file.
- Fixed some logged values (thanks to Jose Alf.).
- Fixed some error handling and cleanup issues (thanks to Jose Alf.).
- Fixed OpenSSL applink detection and MSYS2 MinGW builds.
* Features
- Added the CRLcheckChain service-level option for opt-in full-chain CRL verification.
- Added the new 'transport' service-level option to choose between TLS over TCP and DTLS over UDP.
```

Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected stunnel package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-de8630b736

Plugin Details

Severity: Medium

ID: 335901

File Name: fedora_2026-de8630b736.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/16/2026

Updated: 8/16/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.89

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2026-70368

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:43, p-cpe:/a:fedoraproject:fedora:stunnel

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/7/2026

Vulnerability Publication Date: 8/4/2026

Reference Information

CVE: CVE-2026-70367, CVE-2026-70368