Synopsis
The remote Debian host is missing one or more security-related updates.
Description
The remote Debian 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4795 advisory.
- ------------------------------------------------------------------------- Debian LTS Advisory DLA-4795-1 [email protected] https://www.debian.org/lts/security/ Arnaud Rebillout September 25, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : openssl Version : 3.0.22-1~deb12u1 CVE ID : CVE-2026-42767 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 Debian Bug : 1139674 1145172
Several vulnerabilities have been discovered in OpenSSL, a Secure Socket Layer toolkit providing the SSL and TLS cryptographic protocols for secure communication over the Internet.
CVE-2026-42767
An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.
CVE-2026-54874
Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.
CVE-2026-63072
OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.
CVE-2026-63074
The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.
CVE-2026-63076
OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.
CVE-2026-75803
ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.
For Debian 12 bookworm, these problems have been fixed in version 3.0.22-1~deb12u1.
We recommend that you upgrade your openssl packages.
For the detailed security status of openssl please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/openssl
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Tenable has extracted the preceding description block directly from the Debian security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Upgrade the libcrypto3-udeb packages.
Plugin Details
File Name: debian_DLA-4795.nasl
Agent: unix
Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:libcrypto3-udeb, p-cpe:/a:debian:debian_linux:libssl-dev, p-cpe:/a:debian:debian_linux:libssl-doc, p-cpe:/a:debian:debian_linux:libssl3-udeb, p-cpe:/a:debian:debian_linux:libssl3, p-cpe:/a:debian:debian_linux:openssl
Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l
Exploit Ease: No known exploits are available
Patch Publication Date: 9/25/2026
Vulnerability Publication Date: 6/9/2026