SB2026100654 - Multiple vulnerabilities in LibreSSL
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 vulnerabilities.
1) Improper validation of certificate with host mismatch (CVE-ID: N/A)
CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass hostname mismatch detection.
The vulnerability exists due to incomplete reporting of hostname mismatches in certificate verification callbacks when verifying a peer hostname. A remote attacker can present a certificate with a mismatched hostname to bypass hostname mismatch detection.
The issue concerns verification callbacks that always return 1.
2) Improper Validation of Specified Quantity in Input (CVE-ID: N/A)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass DTLS fragment size validation.
The vulnerability exists due to an incorrect size check in dtls1_preprocess_fragment() when preprocessing DTLS handshake fragments. A remote attacker can supply DTLS fragments to bypass DTLS fragment size validation.
3) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause excessive buffering of DTLS handshake messages.
The vulnerability exists due to insufficient message size limits in DTLS handshake buffering when buffering handshake messages. A remote attacker can supply oversized DTLS handshake messages to cause excessive buffering of DTLS handshake messages.
4) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in DTLS retransmission handling when a retransmission is interrupted. A remote attacker can trigger interrupted DTLS retransmission to trigger an out-of-bounds read.
5) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass OCSP responder authorization.
The vulnerability exists due to improper authorization checks in libtls and ocspcheck(8) when validating OCSP responder authorization. A remote attacker can supply an OCSP response from an unauthorized responder to bypass OCSP responder authorization.
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect enforcement of certificate-chain depth limits.
The vulnerability exists due to an off-by-one error in the X.509 verifier depth checking when validating certificate chains. A remote attacker can supply a certificate chain to cause incorrect enforcement of certificate-chain depth limits.
7) Improper handling of exceptional conditions (CVE-ID: N/A)
CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to prevent verification callbacks from observing a hostname mismatch.
The vulnerability exists due to improper error reporting in certificate verification callback handling when processing a certificate with a hostname mismatch. A remote attacker can present a certificate with a mismatched hostname to prevent verification callbacks from observing a hostname mismatch.
The issue concerns verification callbacks that always return 1.
8) Improper Validation of Specified Quantity in Input (CVE-ID: N/A)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect validation of DTLS fragment sizes.
The vulnerability exists due to an incorrect size check in dtls1_preprocess_fragment() when preprocessing DTLS fragments. A remote attacker can supply DTLS fragments to cause incorrect validation of DTLS fragment sizes.
9) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause excessive buffering of DTLS handshake messages.
The vulnerability exists due to insufficient size limits in DTLS handshake message buffering when buffering handshake messages. A remote attacker can supply DTLS handshake messages to cause excessive buffering of DTLS handshake messages.
10) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an out-of-bounds read.
The vulnerability exists due to a potential out-of-bounds read in DTLS retransmission handling when a retransmission is interrupted. A remote attacker can interact with DTLS retransmission handling under this condition to trigger an out-of-bounds read.
11) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass OCSP responder authorization.
The vulnerability exists due to improper authorization in the OCSP responder authorization checks in libtls and ocspcheck(8) when validating OCSP responder authorization. A remote attacker can provide an OCSP response to bypass OCSP responder authorization.
Remediation
Install update from vendor's website.