- Package:
- src:libcrypt-openssl-x509-perl
- Source:
- src:libcrypt-openssl-x509-perl
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-14 15:15:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for libcrypt-openssl-x509-perl. CVE-2026-58101[0]: | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of | service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns | NULL when an extension's DER value fails to parse. basicC, | ia5string, and auth_att dereference its result without a NULL check. | keyid_data also dereferences akid->keyid, which is NULL for an empty | AKI SEQUENCE (DER 30 00) even when the parse succeeds. A caller | invoking an affected helper on an extension from an untrusted | certificate triggers a SIGSEGV that crashes the Perl process. CVE-2026-58102[1]: | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap | out-of-bounds read via a long certificate extension OID in hv_exts. | When building the extension hash (via extensions(), | extensions_by_long_name(), extensions_by_oid(), or | has_extension_oid()), the code passes OBJ_obj2txt()'s return value | as the hash-key length; because that value is the OID's full text | length rather than the bytes written to the fixed-size buffer (129 | bytes), an OID whose text is longer than the 129-byte buffer causes | a read past the allocation, exposing adjacent heap memory as the | returned hash key. extensions_by_name() uses the static shortname | path and is not affected. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-58101 https://www.cve.org/CVERecord?id=CVE-2026-58101 [1] https://security-tracker.debian.org/tracker/CVE-2026-58102 https://www.cve.org/CVERecord?id=CVE-2026-58102 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libcrypt-openssl-x509-perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142034@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libcrypt-openssl-x509-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 14 Jul 2026 16:48:37 +0200
Source: libcrypt-openssl-x509-perl
Architecture: source
Version: 2.1.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1142034
Changes:
libcrypt-openssl-x509-perl (2.1.3-1) unstable; urgency=medium
.
* Import upstream version 2.1.3.
- Fixed CVE-2026-58102: heap out-of-bounds read in `hv_exts()`.
- Fixed CVE-2026-58101: NULL-pointer dereference in several
`Crypt::OpenSSL::X509::Extension` helpers.
Closes: #1142034
Checksums-Sha1:
8ccfcdc600af8f215ae8e58c194bbd23f6088d61 2792 libcrypt-openssl-x509-perl_2.1.3-1.dsc
814812b88e61d95d50976697f75c36b4087f014d 178318 libcrypt-openssl-x509-perl_2.1.3.orig.tar.gz
1cc6120b92be04d4aaee1811a973ecafb630ba8c 5432 libcrypt-openssl-x509-perl_2.1.3-1.debian.tar.xz
Checksums-Sha256:
a359fc448590ed7811ab341e30c16438f2c1d7b5e0dcc02def57a8fc276f28e0 2792 libcrypt-openssl-x509-perl_2.1.3-1.dsc
0ad965175746ae846b0510b038aa1f96d2ddb8c860fe97cea6fbdc7a055f9f9e 178318 libcrypt-openssl-x509-perl_2.1.3.orig.tar.gz
43537761fe5b17b5f85ef77e0f3dc034d485d2aacbe0ded50a44273e62857b3e 5432 libcrypt-openssl-x509-perl_2.1.3-1.debian.tar.xz
Files:
0e356e290c6f0f45e663092329c25eb8 2792 perl optional libcrypt-openssl-x509-perl_2.1.3-1.dsc
39da0465924533faf4aa5182587e7f12 178318 perl optional libcrypt-openssl-x509-perl_2.1.3.orig.tar.gz
d995ca6a8aecc13a414bdf5b72146424 5432 perl optional libcrypt-openssl-x509-perl_2.1.3-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpWTPVfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgYKuQ/+ITTHPjtM6FHMvqYUrMMx9daQq1mitCe1hiA9wyWRWnNdGSeMDTAFKB8r
80amnrSTHp0JIQumHmRI5KpHPGjFXatrtmKjLWafiVc0gixTV27fpK98/WcmDxQX
VLSiXAqDzuixp3gomBwA4FFD23jiM9YDuSvd5/UoKf19W6hWfHzNl9gFRS6Cm4Wr
5KYJo8iC2omxb6Hoe7RL88tpzVf75fqnrIntMcdahckqqBxuI+PSRK3qEmG10dT4
8R6ZKiU1y8gIJJh+U76A5M9dWj0aWbJ/Xpclvplgk6YjnBHn1BEdxgwSGM2wO2Fj
YBsbtm78/yKW251ECF6R1St8Ri8EQJzdiwpuU0GyKNreq6XAPo5NdBglNGU17jD3
U1Q/q+k4mAAOI+hbAMlezB/bgxF9bDm2uK4D2QU/pev6oXcYBpsnfM4mRZacO6EO
gTgy6o/Bd3PgqY+5kseaXK+euDe6K0zdl4FvnNAagf2v3A44gmcPySu3X79qYzvf
ixpmtmQhs7v4LWcP0oX9fthyx+brdedd68Yz75EDgSp7FzzsvmGMWX0pq4ESwVlF
WFGbfhteXJJyJ6T5FkgNM589Tm6X7CDhD+wHPSNPuiDP2yAUIWeSksXzOpshaop1
CD0BNywULPci/oXRMrRyTfluRYi0LEiMQFlbAhX0NIMaOQpglvg=
=jVn9
-----END PGP SIGNATURE-----