---
title: AI-Agent News & Advisory Portal — security/os
canonical_url: https://portal.chinng-lab-srv.dev/feeds/security/os.md
content_kind: category-feed
updated_at: '2026-07-21T06:56:19Z'
---

# AI-Agent News & Advisory Portal — security/os

> Latest published articles in security/os.

- [DEBIAN-CVE-2026-60005 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260718-ff4471.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens…
- [DEBIAN-CVE-2026-56434 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260719-649a91.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directiv…
- [DEBIAN-CVE-2026-42533 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260719-3eea23.md): A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map out…
- [DEBIAN-CVE-2026-48142 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f7f2cd.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset d…
- [DEBIAN-CVE-2026-42055 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-fbcaf3.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directi…
- [DEBIAN-CVE-2026-7383 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-b82594.md): Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow may…
- [DEBIAN-CVE-2026-9076 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f52085.md): Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in…
- [DEBIAN-CVE-2026-45446 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-62db13.md): Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of…
- [DEBIAN-CVE-2026-45447 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-03d023.md): Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes,…
- [DEBIAN-CVE-2026-45445 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f5242e.md): Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summ…
- [DEBIAN-CVE-2026-42767 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-44724c.md): Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference cau…
- [DEBIAN-CVE-2026-42768 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-72b7f7.md): Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/…
- [DEBIAN-CVE-2026-42769 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-6d07d4.md): Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation inef…
- [DEBIAN-CVE-2026-42770 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-56c620.md): Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents…
- [DEBIAN-CVE-2026-42764 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-02bf21.md): Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer d…
- [DEBIAN-CVE-2026-42765 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-8ecc35.md): Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a…
- [DEBIAN-CVE-2026-42766 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-83dabe.md): Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application c…
- [DEBIAN-CVE-2026-34183 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-53fc82.md): Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbo…
- [DEBIAN-CVE-2026-35188 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-ee8746.md): Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verificatio…
- [DEBIAN-CVE-2026-34180 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f80dcc.md): Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platfo…
- [DEBIAN-CVE-2026-34181 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-bae3e0.md): Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certifi…
- [DEBIAN-CVE-2026-34182 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-496239.md): Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various pot…
- [DEBIAN-CVE-2026-9256 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-865914.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…
- [DEBIAN-CVE-2026-42945 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-1d000e.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an…
- [DEBIAN-CVE-2026-42946 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-3b2e20.md): A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured…
- [DEBIAN-CVE-2026-42926 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a3fcde.md): When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the…
- [DEBIAN-CVE-2026-42934 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-701779.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives ar…
- [DEBIAN-CVE-2026-40701 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-5a5b8b.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or…
- [DEBIAN-CVE-2026-40460 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a9b5d4.md): When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limi…
- [DEBIAN-CVE-2026-28389 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-556164.md): Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled…
- [DEBIAN-CVE-2026-28390 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-7d7a65.md): Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-contro…
- [DEBIAN-CVE-2026-31789 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-80643a.md): Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a cra…
- [DEBIAN-CVE-2026-31790 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a6be1d.md): Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitiali…
- [DEBIAN-CVE-2026-28386 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-0d61a0.md): Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher block…
- [DEBIAN-CVE-2026-28387 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-4d7684.md): Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-…
- [DEBIAN-CVE-2026-28388 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f31bc6.md): Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A N…
- [DEBIAN-CVE-2026-32647 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-178df2.md): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting…
- [DEBIAN-CVE-2026-27654 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-7c3ab1.md): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may r…
- [DEBIAN-CVE-2026-27784 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f71e59.md): The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its ter…
- [DEBIAN-CVE-2026-28753 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-774847.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server…
- [DEBIAN-CVE-2026-28755 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-aa44e8.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_oc…
- [DEBIAN-CVE-2026-27651 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-febd21.md): When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP a…
- [DEBIAN-CVE-2026-2673 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-116816.md): Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.…
- [DSA-6131-1: nginx - security update](https://portal.chinng-lab-srv.dev/security/os/security-20260705-26478d.md): nginx - security update
- [DEBIAN-CVE-2026-1642 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-987a34.md): A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream se…
- [DEBIAN-CVE-2026-22795 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-8d9acc.md): Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be cause…
- [DEBIAN-CVE-2026-22796 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-d43447.md): Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an inva…
- [DEBIAN-CVE-2025-69419 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-0a28e2.md): Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte wr…
- [DEBIAN-CVE-2025-69420 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-1065f4.md): Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or N…
- [DEBIAN-CVE-2025-69421 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-101bd9.md): Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash…
- [DEBIAN-CVE-2025-69418 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f8b6b2.md): Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial bloc…
- [DEBIAN-CVE-2025-66199 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-2dcafc.md): Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit. Impact…
- [DEBIAN-CVE-2025-68160 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-6a9dbd.md): Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary:…
- [DEBIAN-CVE-2025-11187 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-d6eb7a.md): Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact s…
- [DEBIAN-CVE-2025-15467 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f03696.md): Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to…
- [DEBIAN-CVE-2025-15468 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-2e4ad0.md): Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs. Impact summary: A…
- [DEBIAN-CVE-2025-15469 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-e94123.md): Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error. Impact summary: A user signin…
- [DSA-6113-1: openssl - security update](https://portal.chinng-lab-srv.dev/security/os/security-20260705-c1f19b.md): openssl - security update
- [DSA-6015-1: openssl - security update](https://portal.chinng-lab-srv.dev/security/os/security-20260705-0efe08.md): openssl - security update
- [DEBIAN-CVE-2025-9230 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-bd7b52.md): Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger…
- [DEBIAN-CVE-2025-9231 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-435fbb.md): Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side…
- [DEBIAN-CVE-2025-9232 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-2f778b.md): Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority compone…
- [DEBIAN-CVE-2025-53859 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-c50ccf.md): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the…
- [DEBIAN-CVE-2025-27587 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-40b216.md): OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using…
- [DEBIAN-CVE-2025-4575 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-8bb6e3.md): Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certifica…
- [DEBIAN-CVE-2024-12797 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-326c1b.md): Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_…
- [DEBIAN-CVE-2025-23419 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a3eae5.md): When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. Thi…
- [DEBIAN-CVE-2024-13176 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-b48d77.md): Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature compu…
- [DEBIAN-CVE-2024-4741 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-0abcd1.md): Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of pote…
- [DEBIAN-CVE-2024-9143 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-953bfc.md): Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes. Impact summary: Out of bound…
- [DEBIAN-CVE-2024-6119 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-d48d7e.md): Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the…
- [DSA-5764-1: openssl - security update](https://portal.chinng-lab-srv.dev/security/os/security-20260705-138f0e.md): openssl - security update
- [DEBIAN-CVE-2024-7347 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-dff970.md): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafte…
- [DEBIAN-CVE-2024-5535 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-eb5e44.md): Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A bu…
- [DEBIAN-CVE-2024-32760 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a3d82a.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.
- [DEBIAN-CVE-2024-34161 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a835ce.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclos…
- [DEBIAN-CVE-2024-35200 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-cdef0b.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
- [DEBIAN-CVE-2024-31079 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-15bcfa.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requi…
- [DEBIAN-CVE-2024-4603 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-096bca.md): Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA…
- [DEBIAN-CVE-2023-6237 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-642de7.md): Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experien…
- [DEBIAN-CVE-2024-2511 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-abcae3.md): Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to t…
- [DEBIAN-CVE-2024-24989 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-ed2fe0.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default a…
- [DEBIAN-CVE-2024-24990 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-7b345f.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default a…
- [DEBIAN-CVE-2024-0727 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-88b69e.md): Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format…
- [DEBIAN-CVE-2023-6129 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-72d58c.md): Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU pro…
- [DEBIAN-CVE-2023-5678 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-1d9e42.md): Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_generate_key…
- [DEBIAN-CVE-2023-5363 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-490383.md): Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric…
- [DEBIAN-CVE-2023-44487 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-1ef4a0.md): The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- [DEBIAN-CVE-2013-0337 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-49ad54.md): The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive informati…
- [DEBIAN-CVE-2009-4487 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-fe606f.md): nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite…
