Opened 2 months ago
Closed 2 months ago
#23695 closed enhancement (fixed)
stunnel-5.80
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version.
Change History (3)
comment:1 by , 2 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 2 months ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Priority: | normal → elevated |
| Severity: | normal → medium |
| Status: | assigned → new |
comment:3 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-191 has been issued.
Note:
See TracTickets
for help on using tickets.

### Version 5.80, 2026.08.04, urgency: HIGH * Security bugfixes - CVE-2026-70368: Fixed an out-of-bounds memory access triggered by logging attacker-controlled protocol messages longer than 1,024 bytes (thanks to AISLE Research and Clemens Lang). - CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost destination filter using alternate local-address encodings and interface-scoped IPv6 destinations (thanks to AISLE Research and Clemens Lang). - Restricted Windows GUI/service control pipes to local clients. * Bugfixes - Fixed concurrent DTLS handshakes from clients sharing an IP address. - Fixed version reporting in builds from source. - Rejected stream-oriented protocol negotiation with the UDP transport during configuration validation. * Features - Added the "CRLcheckChain" service-level option for opt-in full-chain CRL verification.Fixed at ab8d02c682. Leaving open for SA.