| Name | CVE-2026-32877 |
| Description | Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded value was of the expected length prior to comparison. An invalid ciphertext can cause a heap over-read of up to 31 bytes, resulting in a crash or potentially other undefined behavior. This issue has been patched in version 3.11.0. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| botan (PTS) | bullseye | 2.17.3+dfsg-2 | vulnerable |
| bookworm | 2.19.3+dfsg-1+deb12u1 | vulnerable | |
| trixie | 2.19.5+dfsg-4 | vulnerable | |
| botan3 (PTS) | trixie | 3.7.1+dfsg-2 | vulnerable |
| forky, sid | 3.12.0+dfsg-2 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| botan | source | (unstable) | (unfixed) | |||
| botan3 | source | experimental | 3.11.0+dfsg-1 | |||
| botan3 | source | (unstable) | 3.11.0+dfsg-2 |
[trixie] - botan <no-dsa> (Minor issue)
[bookworm] - botan <postponed> (Minor issue; SM2 C3 heap over-read; fix only in 3.11.0)
[bullseye] - botan <postponed> (Minor issue; SM2 C3 heap over-read; fix only in 3.11.0)
https://github.com/randombit/botan/security/advisories/GHSA-7jj6-4r42-w9h6
https://github.com/randombit/botan/commit/f3c31f96f58f1d1d482032d8f4286dc9ebbc6712 (3.11.0)