{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch (ssl/record/rec_layer_d1.c)\n     - debian/patches/CVE-2026-54874.patch: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch (ssl/record/rec_layer_d1.c)\n     - CVE-2026-54874\n   * SECURITY UPDATE: fix 8-byte out-of-bounds heap write in CMS AES-WRAP-PAD key unwrapping (crypto/cms/cms_kari.c)\n     - debian/patches/CVE-2026-63072.patch: fix 8-byte out-of-bounds heap write in CMS AES-WRAP-PAD key unwrapping (crypto/cms/cms_kari.c)\n     - debian/patches/CVE-2026-63072-test.patch: add the upstream regression test for the AES-WRAP-PAD unwrap overflow (test/cmsapitest.c)\n     - CVE-2026-63072",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788264910",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788264910"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/advisories/2026/clsa-2026_1788264910.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-01T12:15:53Z",
      "generator": {
        "date": "2026-09-01T12:15:53Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788264910",
      "initial_release_date": "2026-09-01T12:15:53Z",
      "revision_history": [
        {
          "date": "2026-09-01T12:15:53Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2026-54874, CVE-2026-63072"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                "product": {
                  "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                  "product_id": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1n-0%2Bdeb10u6%2Btuxcare.els6?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                "product": {
                  "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                  "product_id": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1n-0%2Bdeb10u6%2Btuxcare.els6?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                "product": {
                  "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                  "product_id": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1n-0%2Bdeb10u6%2Btuxcare.els6?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                "product": {
                  "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                  "product_id": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1n-0%2Bdeb10u6%2Btuxcare.els5?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                "product": {
                  "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                  "product_id": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1n-0%2Bdeb10u6%2Btuxcare.els5?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                "product": {
                  "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                  "product_id": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1n-0%2Bdeb10u6%2Btuxcare.els5?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                "product": {
                  "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                  "product_id": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1n-0%2Bdeb10u6%2Btuxcare.els4?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                "product": {
                  "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                  "product_id": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1n-0%2Bdeb10u6%2Btuxcare.els4?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                "product": {
                  "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                  "product_id": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1n-0%2Bdeb10u6%2Btuxcare.els4?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                "product": {
                  "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                  "product_id": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1n-0%2Bdeb10u6%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                "product": {
                  "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                  "product_id": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1n-0%2Bdeb10u6%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                "product": {
                  "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                  "product_id": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1n-0%2Bdeb10u6%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                "product": {
                  "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                  "product_id": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1n-0%2Bdeb10u6%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                "product": {
                  "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                  "product_id": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1n-0%2Bdeb10u6%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                "product": {
                  "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                  "product_id": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1n-0%2Bdeb10u6%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                "product": {
                  "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                  "product_id": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1n-0%2Bdeb10u6%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                "product": {
                  "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                  "product_id": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1n-0%2Bdeb10u6%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                "product": {
                  "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                  "product_id": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1n-0%2Bdeb10u6%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all",
                "product": {
                  "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all",
                  "product_id": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-doc@1.1.1n-0%2Bdeb10u6%2Btuxcare.els6?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all",
                "product": {
                  "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all",
                  "product_id": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-doc@1.1.1n-0%2Bdeb10u6%2Btuxcare.els5?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all",
                "product": {
                  "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all",
                  "product_id": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-doc@1.1.1n-0%2Bdeb10u6%2Btuxcare.els4?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all",
                "product": {
                  "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all",
                  "product_id": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-doc@1.1.1n-0%2Bdeb10u6%2Btuxcare.els3?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all",
                "product": {
                  "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all",
                  "product_id": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-doc@1.1.1n-0%2Bdeb10u6%2Btuxcare.els2?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all",
                "product": {
                  "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all",
                  "product_id": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-doc@1.1.1n-0%2Bdeb10u6%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64 as a component of Debian 10",
          "product_id": "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64"
        },
        "product_reference": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all as a component of Debian 10",
          "product_id": "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all"
        },
        "product_reference": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64"
        },
        "product_reference": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64"
        },
        "product_reference": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64"
        },
        "product_reference": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64"
        },
        "product_reference": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64"
        },
        "product_reference": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all as a component of Debian 10",
          "product_id": "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all"
        },
        "product_reference": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64"
        },
        "product_reference": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all as a component of Debian 10",
          "product_id": "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all"
        },
        "product_reference": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64 as a component of Debian 10",
          "product_id": "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64"
        },
        "product_reference": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64"
        },
        "product_reference": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64"
        },
        "product_reference": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all as a component of Debian 10",
          "product_id": "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all"
        },
        "product_reference": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64 as a component of Debian 10",
          "product_id": "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64"
        },
        "product_reference": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64"
        },
        "product_reference": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64"
        },
        "product_reference": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all as a component of Debian 10",
          "product_id": "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all"
        },
        "product_reference": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64"
        },
        "product_reference": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64"
        },
        "product_reference": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64"
        },
        "product_reference": "libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64"
        },
        "product_reference": "openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all as a component of Debian 10",
          "product_id": "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all"
        },
        "product_reference": "libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64"
        },
        "product_reference": "libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-54874",
      "cwe": {
        "id": "CWE-405",
        "name": "Asymmetric Resource Consumption (Amplification)"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64"
        ],
        "known_affected": [
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-54874"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23",
          "url": "https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40",
          "url": "https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382",
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107",
          "url": "https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c",
          "url": "https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260825.txt",
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        }
      ],
      "release_date": "2026-08-25T13:19:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T12:15:12.612343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1788264910",
          "product_ids": [
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788264910"
        },
        {
          "category": "none_available",
          "date": "2026-08-25T13:19:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-63072",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64"
        ],
        "known_affected": [
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
          "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all",
          "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
          "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
          "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-63072"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756",
          "url": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42",
          "url": "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335",
          "url": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a",
          "url": "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382",
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260825.txt",
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        }
      ],
      "release_date": "2026-08-25T13:19:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T12:15:12.612343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1788264910",
          "product_ids": [
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els6.all",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els6.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788264910"
        },
        {
          "category": "none_available",
          "date": "2026-08-25T13:19:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
            "Debian-10:libssl-dev-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els1.all",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els2.all",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els3.all",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els4.all",
            "Debian-10:libssl-doc-0:1.1.1n-0+deb10u6+tuxcare.els5.all",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
            "Debian-10:libssl1.1-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els1.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els2.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els3.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els4.amd64",
            "Debian-10:openssl-0:1.1.1n-0+deb10u6+tuxcare.els5.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}