Opened 2 months ago

Closed 2 months ago

#23695 closed enhancement (fixed)

stunnel-5.80

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (3)

comment:1 by Joe Locash, 2 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 2 months ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Priority: normal → elevated
Severity: normal → medium
Status: assigned → new
### Version 5.80, 2026.08.04, urgency: HIGH
* Security bugfixes
  - CVE-2026-70368: Fixed an out-of-bounds memory access triggered by
    logging attacker-controlled protocol messages longer than 1,024 bytes
    (thanks to AISLE Research and Clemens Lang).
  - CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost
    destination filter using alternate local-address encodings and
    interface-scoped IPv6 destinations (thanks to AISLE Research and
    Clemens Lang).
  - Restricted Windows GUI/service control pipes to local clients.
* Bugfixes
  - Fixed concurrent DTLS handshakes from clients sharing an IP address.
  - Fixed version reporting in builds from source.
  - Rejected stream-oriented protocol negotiation with the UDP transport
    during configuration validation.
* Features
  - Added the "CRLcheckChain" service-level option for opt-in
    full-chain CRL verification.

Fixed at ab8d02c682. Leaving open for SA.

comment:3 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-191 has been issued.

Note: See TracTickets for help on using tickets.