#1143970 libcrypt-openssl-pkcs12-perl: CVE-2026-17510

#1143970#5
Date:
2026-08-09 05:46:20 UTC
From:
To:
Hi,

The following vulnerability was published for libcrypt-openssl-pkcs12-perl.

CVE-2026-17510[0]:
| Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL
| pointer dereference in print_attribute via a zero length BMPSTRING
| attribute.  print_attribute() sizes the destination buffer for a
| BMPSTRING attribute from its declared byte length with
| `Renew(*attribute, length, char)`. A zero length attribute makes
| that a zero size reallocation, which Perl implements as a free
| returning NULL, so the buffer pointer becomes NULL, the following
| `strncpy` copies nothing, and the caller dereferences NULL in the
| `strlen()` it passes to `newSVpvn()`. A zero length BMPSTRING is
| even length, so the ASN.1 decoder accepts it and the value reaches
| this code. The UTF8STRING, OCTET STRING and BIT STRING arms size on
| `length + 1` or `length * 4 + 1` and are unaffected.  Any caller
| that passes an untrusted PKCS#12 file to info_as_hash() can crash
| the process. info() prints attribute values directly without sizing
| a buffer and is unaffected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-17510
https://www.cve.org/CVERecord?id=CVE-2026-17510
[1] https://lists.security.metacpan.org/cve-announce/msg/42524422/

Regards,
Salvatore

#1143970#14
Date:
2026-08-09 10:48:49 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libcrypt-openssl-pkcs12-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143970@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libcrypt-openssl-pkcs12-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 09 Aug 2026 12:35:51 +0200
Source: libcrypt-openssl-pkcs12-perl
Architecture: source
Version: 1.98-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1143970
Changes:
 libcrypt-openssl-pkcs12-perl (1.98-1) unstable; urgency=medium
 .
   * Team upload.
   * Import upstream version 1.98.
     - Security: fix NULL pointer dereference in `print_attribute()`'s
       `V_ASN1_BMPSTRING` branch.
       CVE-2026-17510
     (Closes: #1143970)
   * Upstream TODO file is gone.
Checksums-Sha1:
 d6033ca809fcde48f68d4c01a6e79c1fdcb86416 2736 libcrypt-openssl-pkcs12-perl_1.98-1.dsc
 a6272a9fec8c4d5e5254249a3a750c6b79e7fade 234890 libcrypt-openssl-pkcs12-perl_1.98.orig.tar.gz
 7dc05193d7a1b9c887633f2fd66a0cf312cdaefe 3384 libcrypt-openssl-pkcs12-perl_1.98-1.debian.tar.xz
 cf9aba98a16eb0e7140dcc5d2f8779c60e3c78da 333892 libcrypt-openssl-pkcs12-perl_1.98-1.git.tar.xz
 fc3ec2d2d77bbf038f4d9f1520c4ba9bad7237a8 17632 libcrypt-openssl-pkcs12-perl_1.98-1_source.buildinfo
Checksums-Sha256:
 bd0c0fe811ee67020e447c1661707550455c414584103d67fd402ac86825d61c 2736 libcrypt-openssl-pkcs12-perl_1.98-1.dsc
 b3b93dbbb61f8b39ba355ff6f393d233fabbf963678b137787c19ef1275657cb 234890 libcrypt-openssl-pkcs12-perl_1.98.orig.tar.gz
 9c6a62fbb421001f4e4f3620ab6c2abc33b8f5275d8728a268a786cecb7db81e 3384 libcrypt-openssl-pkcs12-perl_1.98-1.debian.tar.xz
 76b12c25dc76cab73c1ceb12c1f2e561d3d2f0e00fa5a769430a5a7e02b384b4 333892 libcrypt-openssl-pkcs12-perl_1.98-1.git.tar.xz
 92f184271cc4acd2dd4c75fdb21f679497dff9f9e193e2afb08983a1f1231a79 17632 libcrypt-openssl-pkcs12-perl_1.98-1_source.buildinfo
Files:
 c6179fbbddd4568ded80aa9829e90bc6 2736 perl optional libcrypt-openssl-pkcs12-perl_1.98-1.dsc
 3045d7f3b78c6de3e4939f6197b7753a 234890 perl optional libcrypt-openssl-pkcs12-perl_1.98.orig.tar.gz
 ee4dd777059ca7b121a419c36201fcb8 3384 perl optional libcrypt-openssl-pkcs12-perl_1.98-1.debian.tar.xz
 54fe7b271dc477fa86ab02667b27fa10 333892 perl None libcrypt-openssl-pkcs12-perl_1.98-1.git.tar.xz
 fdc2052cd8c5ed4302df1011bf8a0808 17632 perl optional libcrypt-openssl-pkcs12-perl_1.98-1_source.buildinfo
Git-Tag-Info: tag=a59f7699fc81b3bfa7d4694a6427ee7e8be7b6a6 fp=d1e1316e93a760a8104d85fabb3a68018649aa06
Git-Tag-Tagger: gregor herrmann <gregoa@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp4WPMACgkQYG0ITkaD
wHkU9hAAsNrl6+ug+NRvvtOTPkwD4v65t1YjVPfGfHg1iwDecZlrWiL7PdElNH8r
Z6lc3QCY+mC1xvRbRzd73+8/ONUwccsYtILvZmnwmt3UpXHm9somFsy6aNZLLi+A
2Be5R3PkDV0LapCOxTAFEgP90RqND7k0oJauEKlvxuYmIRdR8iC7LbYWB/isYkVa
cdcDKAcF8uE/CmsJ+AvfprelSjIeCzc/itSw0aNVWHnoiQ874e2DHhu1FWxFfO95
pEbAQ1O+JkocLVmeSma8vZW4QrJUJ8OeFsnnBl68xDsMB9OfKxpYDQ/86bGJGJGy
LuxH03s3i66kgNCfKgMUyjXrJRnBfBfo19FK0t00M9mlVMPCUoBLiIsECmeNSN2C
cFEhUALbX19BOY42xJWXJzXIElRmUW/70wsmK8YKBrAjPsRbkQmoyh2nbFYGCsaO
OlPpOKzRNc2B5tuzcsbFC1iMEDfriqismbmnCJSezI/NpqImdqf2ifmKHNsPoxyO
H42V6sZnjK2vfAwhtrN3jEVyomStCwuzEUFsRxEktQPv6pot30ivL6mSd+1gmvys
lczZMT/tm3tTsjmMRzA0ztTqk58jg/f66Hr3grOd1UHYHHB6RBQ8pYkT6SvdF3pP
o6GCm+xqVdj2z/F1mO64Um9pqM0A6TGwyczu5V6jdPhO9G13beA=
=+iYw
-----END PGP SIGNATURE-----