{"id":"CLSA-2026-1778787445","summary":"Fix CVE(s): CVE-2026-28387, CVE-2026-28388, CVE-2026-28389","details":"   * SECURITY UPDATE: Use-after-free / heap corruption in dane_match() of\n     the X.509 verifier where the cached DANE-matched certificate was freed\n     via OPENSSL_free() instead of X509_free(), bypassing the X509 reference\n     counting and freeing certificate fields that may still be referenced by\n     other holders. An attacker able to influence the DANE TLSA records used\n     during certificate verification can trigger memory corruption.\n     - debian/patches/CVE-2026-28387.patch: replace OPENSSL_free(dane-\u003emcert)\n       with X509_free(dane-\u003emcert) in dane_match() in crypto/x509/x509_vfy.c.\n     - CVE-2026-28387\n   * SECURITY UPDATE: NULL pointer dereference in check_delta_base() of\n     the X.509 CRL verifier when a delta CRL lacks the CRL Number extension.\n     A remote attacker controlling a delta CRL can trigger a crash, leading\n     to denial of service in applications using -crl_check with -use_deltas.\n     - debian/patches/CVE-2026-28388.patch: NULL-check delta-\u003ecrl_number\n       before passing it to ASN1_INTEGER_cmp() in check_delta_base() in\n       crypto/x509/x509_vfy.c, and ship the upstream test fixtures and\n       verify recipe.\n     - CVE-2026-28388\n   * SECURITY UPDATE: NULL pointer dereference in dh_cms_set_shared_info()\n     and ecdh_cms_set_shared_info() when a CMS KeyAgreeRecipientInfo has\n     no KeyEncryptionAlgorithmIdentifier parameters field, allowing a\n     remote attacker to trigger a denial of service via crafted CMS data.\n     - debian/patches/CVE-2026-28389.patch: NULL-check alg-\u003eparameter\n       before accessing its type in crypto/dh/dh_ameth.c and\n       crypto/ec/ec_ameth.c.\n     - CVE-2026-28389","modified":"2026-06-04T09:47:31.384632610Z","published":"2026-05-14T22:19:12Z","upstream":["CVE-2026-28387","CVE-2026-28388","CVE-2026-28389"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu18.04els/CLSA-2026-1778787445.html"}],"affected":[{"package":{"name":"libssl-dev","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/libssl-dev?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.1~18.04.23+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1778787445.json"}},{"package":{"name":"libssl-doc","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/libssl-doc?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.1~18.04.23+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1778787445.json"}},{"package":{"name":"libssl1.1","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/libssl1.1?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.1~18.04.23+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1778787445.json"}},{"package":{"name":"openssl","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/openssl?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.1~18.04.23+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1778787445.json"}}],"schema_version":"1.7.5"}