SB2026100654 - Multiple vulnerabilities in LibreSSL



SB2026100654 - Multiple vulnerabilities in LibreSSL

Published: October 6, 2026

Security Bulletin ID SB2026100654
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 11
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 82% Low 18%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 11 vulnerabilities.


1) Improper validation of certificate with host mismatch (CVE-ID: N/A)

CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass hostname mismatch detection.

The vulnerability exists due to incomplete reporting of hostname mismatches in certificate verification callbacks when verifying a peer hostname. A remote attacker can present a certificate with a mismatched hostname to bypass hostname mismatch detection.

The issue concerns verification callbacks that always return 1.


2) Improper Validation of Specified Quantity in Input (CVE-ID: N/A)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass DTLS fragment size validation.

The vulnerability exists due to an incorrect size check in dtls1_preprocess_fragment() when preprocessing DTLS handshake fragments. A remote attacker can supply DTLS fragments to bypass DTLS fragment size validation.


3) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause excessive buffering of DTLS handshake messages.

The vulnerability exists due to insufficient message size limits in DTLS handshake buffering when buffering handshake messages. A remote attacker can supply oversized DTLS handshake messages to cause excessive buffering of DTLS handshake messages.


4) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an out-of-bounds read.

The vulnerability exists due to an out-of-bounds read in DTLS retransmission handling when a retransmission is interrupted. A remote attacker can trigger interrupted DTLS retransmission to trigger an out-of-bounds read.


5) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass OCSP responder authorization.

The vulnerability exists due to improper authorization checks in libtls and ocspcheck(8) when validating OCSP responder authorization. A remote attacker can supply an OCSP response from an unauthorized responder to bypass OCSP responder authorization.


6) Off-by-one (CVE-ID: N/A)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect enforcement of certificate-chain depth limits.

The vulnerability exists due to an off-by-one error in the X.509 verifier depth checking when validating certificate chains. A remote attacker can supply a certificate chain to cause incorrect enforcement of certificate-chain depth limits.


7) Improper handling of exceptional conditions (CVE-ID: N/A)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to prevent verification callbacks from observing a hostname mismatch.

The vulnerability exists due to improper error reporting in certificate verification callback handling when processing a certificate with a hostname mismatch. A remote attacker can present a certificate with a mismatched hostname to prevent verification callbacks from observing a hostname mismatch.

The issue concerns verification callbacks that always return 1.


8) Improper Validation of Specified Quantity in Input (CVE-ID: N/A)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect validation of DTLS fragment sizes.

The vulnerability exists due to an incorrect size check in dtls1_preprocess_fragment() when preprocessing DTLS fragments. A remote attacker can supply DTLS fragments to cause incorrect validation of DTLS fragment sizes.


9) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause excessive buffering of DTLS handshake messages.

The vulnerability exists due to insufficient size limits in DTLS handshake message buffering when buffering handshake messages. A remote attacker can supply DTLS handshake messages to cause excessive buffering of DTLS handshake messages.


10) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger an out-of-bounds read.

The vulnerability exists due to a potential out-of-bounds read in DTLS retransmission handling when a retransmission is interrupted. A remote attacker can interact with DTLS retransmission handling under this condition to trigger an out-of-bounds read.


11) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass OCSP responder authorization.

The vulnerability exists due to improper authorization in the OCSP responder authorization checks in libtls and ocspcheck(8) when validating OCSP responder authorization. A remote attacker can provide an OCSP response to bypass OCSP responder authorization.


Remediation

Install update from vendor's website.