Debian dla-4795 : libcrypto3-udeb - security update

critical Nessus Plugin ID 350322

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4795 advisory.

- ------------------------------------------------------------------------- Debian LTS Advisory DLA-4795-1 [email protected] https://www.debian.org/lts/security/ Arnaud Rebillout September 25, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : openssl Version : 3.0.22-1~deb12u1 CVE ID : CVE-2026-42767 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 Debian Bug : 1139674 1145172

Several vulnerabilities have been discovered in OpenSSL, a Secure Socket Layer toolkit providing the SSL and TLS cryptographic protocols for secure communication over the Internet.

CVE-2026-42767

An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.

CVE-2026-54874

Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.

CVE-2026-63072

OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.

CVE-2026-63074

The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.

CVE-2026-63076

OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.

CVE-2026-75803

ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.

For Debian 12 bookworm, these problems have been fixed in version 3.0.22-1~deb12u1.

We recommend that you upgrade your openssl packages.

For the detailed security status of openssl please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/openssl

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the libcrypto3-udeb packages.

See Also

https://packages.debian.org/source/bookworm/openssl

https://security-tracker.debian.org/tracker/CVE-2026-42767

https://security-tracker.debian.org/tracker/CVE-2026-54874

https://security-tracker.debian.org/tracker/CVE-2026-63072

https://security-tracker.debian.org/tracker/CVE-2026-63074

https://security-tracker.debian.org/tracker/CVE-2026-63076

https://security-tracker.debian.org/tracker/CVE-2026-75803

https://security-tracker.debian.org/tracker/source-package/openssl

Plugin Details

Severity: Critical

ID: 350322

File Name: debian_DLA-4795.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/25/2026

Updated: 9/25/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

Percentile: 96.11

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-75803

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:libcrypto3-udeb, p-cpe:/a:debian:debian_linux:libssl-dev, p-cpe:/a:debian:debian_linux:libssl-doc, p-cpe:/a:debian:debian_linux:libssl3-udeb, p-cpe:/a:debian:debian_linux:libssl3, p-cpe:/a:debian:debian_linux:openssl

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 9/25/2026

Vulnerability Publication Date: 6/9/2026

Reference Information

CVE: CVE-2026-42767, CVE-2026-54874, CVE-2026-63072, CVE-2026-63074, CVE-2026-63076, CVE-2026-75803

IAVA: 2026-A-0589-S, 2026-A-0878