{"id":"CLSA-2026-1777999127","summary":"Fix CVE(s): CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390","details":"   * SECURITY UPDATE: fix UAF/double-free in DANE client by using X509_free() for dane-\u003emcert\n     - debian/patches/CVE-2026-28387.patch: fix UAF/double-free in DANE client by using X509_free() for dane-\u003emcert\n     - CVE-2026-28387\n   * SECURITY UPDATE: NULL check delta-\u003ecrl_number before ASN1_INTEGER_cmp() in check_delta_base()\n     - debian/patches/CVE-2026-28388.patch: NULL check delta-\u003ecrl_number before ASN1_INTEGER_cmp() in check_delta_base()\n     - CVE-2026-28388\n   * SECURITY UPDATE: NULL check alg-\u003eparameter in [ec]dh_cms_set_shared_info() before deref\n     - debian/patches/CVE-2026-28389.patch: NULL check alg-\u003eparameter in [ec]dh_cms_set_shared_info() before deref\n     - CVE-2026-28389\n   * SECURITY UPDATE: NULL check plab-\u003eparameter in rsa_cms_decrypt() before deref\n     - debian/patches/CVE-2026-28390.patch: NULL check plab-\u003eparameter in rsa_cms_decrypt() before deref\n     - CVE-2026-28390","modified":"2026-06-04T09:45:22.230063059Z","published":"2026-05-05T16:38:52Z","upstream":["CVE-2026-28387","CVE-2026-28388","CVE-2026-28389","CVE-2026-28390"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777999127.html"}],"affected":[{"package":{"name":"libssl-dev","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libssl-dev?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1n-0+deb10u6+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1777999127.json"}},{"package":{"name":"libssl-doc","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libssl-doc?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1n-0+deb10u6+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1777999127.json"}},{"package":{"name":"libssl1.1","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libssl1.1?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1n-0+deb10u6+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1777999127.json"}},{"package":{"name":"openssl","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/openssl?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1n-0+deb10u6+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1777999127.json"}}],"schema_version":"1.7.5"}