CVE-2026-2673

NameCVE-2026-2673
DescriptionIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the exp ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1130650

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssl (PTS)bullseye1.1.1w-0+deb11u1fixed
bullseye (security)1.1.1w-0+deb11u5fixed
bookworm3.0.18-1~deb12u1fixed
bookworm (security)3.0.18-1~deb12u2fixed
trixie3.5.4-1~deb13u1vulnerable
trixie (security)3.5.4-1~deb13u2vulnerable
forky3.5.5-1vulnerable
sid3.6.1-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensslsourcebullseye(not affected)
opensslsourcebookworm(not affected)
opensslsource(unstable)(unfixed)1130650

Notes

[trixie] - openssl <no-dsa> (Minor issue)
[bookworm] - openssl <not-affected> (Only affects 3.5 and later)
[bullseye] - openssl <not-affected> (Only affects 3.5 and later)
https://openssl-library.org/news/secadv/20260313.txt
Fixed by: https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34 (openssl-3.5)
Fixed by: https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f (openssl-3.6)

Search for package or bug name: Reporting problems