Vulnerabilidad crítica (CVSS 9.1) en OpenSSL. Publicada el 25 de agosto de 2026. Afecta a Debian 12. Corregida en Debian 13 (3.5.7-1~deb13u2) y Debian 14 (3.6.4-1). Sin parche todavía para Debian 12.
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and ex
Descripción original en inglés: todavía no se ha traducido.
| Distribución | Versión del paquete |
|---|---|
| Debian 13 | 3.5.7-1~deb13u2 |
| Debian 14 | 3.6.4-1 |
Datos de OSV.dev, publicados bajo licencia CC BY 4.0. La severidad es la puntuación base CVSS 3.1 calculada a partir del vector publicado. Esta ficha se genera automáticamente y no sustituye al aviso oficial de tu distribución; así se elabora la lista.
Soporte Linux y DevOps en español