{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: use-after-free in PKCS7_verify\n     - debian/patches/openssl-1.1.1-cve-2026-45447.patch: free the BIO chain\n       explicitly and stop at the caller-supplied indata BIO so a crafted\n       PKCS#7 / S-MIME message with an empty digestAlgorithms ASN.1 SET can no\n       longer make OpenSSL free a caller-owned BIO in PKCS7_verify()\n     - CVE-2026-45447",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1781799687",
        "url": "https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1781799687"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_common/debian10/advisories/2026/clsa-2026_1781799687.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-18T16:22:22Z",
      "generator": {
        "date": "2026-06-18T16:22:22Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1781799687",
      "initial_release_date": "2026-06-18T16:22:22Z",
      "revision_history": [
        {
          "date": "2026-06-18T16:22:22Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2026-45447"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-openssl-doc-0:1.1.1w-3.5.all",
                "product": {
                  "name": "alt-openssl-doc-0:1.1.1w-3.5.all",
                  "product_id": "alt-openssl-doc-0:1.1.1w-3.5.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-doc@1.1.1w-3.5?arch=all&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-doc-0:1.1.1w-3.4.all",
                "product": {
                  "name": "alt-openssl-doc-0:1.1.1w-3.4.all",
                  "product_id": "alt-openssl-doc-0:1.1.1w-3.4.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-doc@1.1.1w-3.4?arch=all&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-doc-0:1.1.1w-3.2.all",
                "product": {
                  "name": "alt-openssl-doc-0:1.1.1w-3.2.all",
                  "product_id": "alt-openssl-doc-0:1.1.1w-3.2.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-doc@1.1.1w-3.2?arch=all&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-doc-0:1.1.1w-3.1.all",
                "product": {
                  "name": "alt-openssl-doc-0:1.1.1w-3.1.all",
                  "product_id": "alt-openssl-doc-0:1.1.1w-3.1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-doc@1.1.1w-3.1?arch=all&os_name=debian&os_version=10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-openssl-dev-0:1.1.1w-3.5.amd64",
                "product": {
                  "name": "alt-openssl-dev-0:1.1.1w-3.5.amd64",
                  "product_id": "alt-openssl-dev-0:1.1.1w-3.5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-dev@1.1.1w-3.5?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-libs-0:1.1.1w-3.5.amd64",
                "product": {
                  "name": "alt-openssl-libs-0:1.1.1w-3.5.amd64",
                  "product_id": "alt-openssl-libs-0:1.1.1w-3.5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-libs@1.1.1w-3.5?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-0:1.1.1w-3.5.amd64",
                "product": {
                  "name": "alt-openssl-0:1.1.1w-3.5.amd64",
                  "product_id": "alt-openssl-0:1.1.1w-3.5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl@1.1.1w-3.5?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-libs-0:1.1.1w-3.4.amd64",
                "product": {
                  "name": "alt-openssl-libs-0:1.1.1w-3.4.amd64",
                  "product_id": "alt-openssl-libs-0:1.1.1w-3.4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-libs@1.1.1w-3.4?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-dev-0:1.1.1w-3.4.amd64",
                "product": {
                  "name": "alt-openssl-dev-0:1.1.1w-3.4.amd64",
                  "product_id": "alt-openssl-dev-0:1.1.1w-3.4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-dev@1.1.1w-3.4?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-0:1.1.1w-3.4.amd64",
                "product": {
                  "name": "alt-openssl-0:1.1.1w-3.4.amd64",
                  "product_id": "alt-openssl-0:1.1.1w-3.4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl@1.1.1w-3.4?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-dev-0:1.1.1w-3.2.amd64",
                "product": {
                  "name": "alt-openssl-dev-0:1.1.1w-3.2.amd64",
                  "product_id": "alt-openssl-dev-0:1.1.1w-3.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-dev@1.1.1w-3.2?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-0:1.1.1w-3.2.amd64",
                "product": {
                  "name": "alt-openssl-0:1.1.1w-3.2.amd64",
                  "product_id": "alt-openssl-0:1.1.1w-3.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl@1.1.1w-3.2?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-libs-0:1.1.1w-3.2.amd64",
                "product": {
                  "name": "alt-openssl-libs-0:1.1.1w-3.2.amd64",
                  "product_id": "alt-openssl-libs-0:1.1.1w-3.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-libs@1.1.1w-3.2?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-libs-0:1.1.1w-3.1.amd64",
                "product": {
                  "name": "alt-openssl-libs-0:1.1.1w-3.1.amd64",
                  "product_id": "alt-openssl-libs-0:1.1.1w-3.1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-libs@1.1.1w-3.1?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-dev-0:1.1.1w-3.1.amd64",
                "product": {
                  "name": "alt-openssl-dev-0:1.1.1w-3.1.amd64",
                  "product_id": "alt-openssl-dev-0:1.1.1w-3.1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl-dev@1.1.1w-3.1?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-0:1.1.1w-3.1.amd64",
                "product": {
                  "name": "alt-openssl-0:1.1.1w-3.1.amd64",
                  "product_id": "alt-openssl-0:1.1.1w-3.1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-openssl@1.1.1w-3.1?arch=amd64&os_name=debian&os_version=10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-doc-0:1.1.1w-3.5.all as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-doc-0:1.1.1w-3.5.all"
        },
        "product_reference": "alt-openssl-doc-0:1.1.1w-3.5.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-dev-0:1.1.1w-3.5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-dev-0:1.1.1w-3.5.amd64"
        },
        "product_reference": "alt-openssl-dev-0:1.1.1w-3.5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-libs-0:1.1.1w-3.5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-libs-0:1.1.1w-3.5.amd64"
        },
        "product_reference": "alt-openssl-libs-0:1.1.1w-3.5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-0:1.1.1w-3.5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-0:1.1.1w-3.5.amd64"
        },
        "product_reference": "alt-openssl-0:1.1.1w-3.5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-libs-0:1.1.1w-3.4.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-libs-0:1.1.1w-3.4.amd64"
        },
        "product_reference": "alt-openssl-libs-0:1.1.1w-3.4.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-dev-0:1.1.1w-3.4.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-dev-0:1.1.1w-3.4.amd64"
        },
        "product_reference": "alt-openssl-dev-0:1.1.1w-3.4.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-doc-0:1.1.1w-3.4.all as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-doc-0:1.1.1w-3.4.all"
        },
        "product_reference": "alt-openssl-doc-0:1.1.1w-3.4.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-0:1.1.1w-3.4.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-0:1.1.1w-3.4.amd64"
        },
        "product_reference": "alt-openssl-0:1.1.1w-3.4.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-dev-0:1.1.1w-3.2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-dev-0:1.1.1w-3.2.amd64"
        },
        "product_reference": "alt-openssl-dev-0:1.1.1w-3.2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-0:1.1.1w-3.2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-0:1.1.1w-3.2.amd64"
        },
        "product_reference": "alt-openssl-0:1.1.1w-3.2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-doc-0:1.1.1w-3.2.all as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-doc-0:1.1.1w-3.2.all"
        },
        "product_reference": "alt-openssl-doc-0:1.1.1w-3.2.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-libs-0:1.1.1w-3.2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-libs-0:1.1.1w-3.2.amd64"
        },
        "product_reference": "alt-openssl-libs-0:1.1.1w-3.2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-libs-0:1.1.1w-3.1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-libs-0:1.1.1w-3.1.amd64"
        },
        "product_reference": "alt-openssl-libs-0:1.1.1w-3.1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-doc-0:1.1.1w-3.1.all as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-doc-0:1.1.1w-3.1.all"
        },
        "product_reference": "alt-openssl-doc-0:1.1.1w-3.1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-dev-0:1.1.1w-3.1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-dev-0:1.1.1w-3.1.amd64"
        },
        "product_reference": "alt-openssl-dev-0:1.1.1w-3.1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-0:1.1.1w-3.1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:alt-openssl-0:1.1.1w-3.1.amd64"
        },
        "product_reference": "alt-openssl-0:1.1.1w-3.1.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-45447",
      "cwe": {
        "id": "CWE-825",
        "name": "Expired Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-10:alt-openssl-0:1.1.1w-3.5.amd64",
          "Debian-10:alt-openssl-dev-0:1.1.1w-3.5.amd64",
          "Debian-10:alt-openssl-doc-0:1.1.1w-3.5.all",
          "Debian-10:alt-openssl-libs-0:1.1.1w-3.5.amd64"
        ],
        "known_affected": [
          "Debian-10:alt-openssl-0:1.1.1w-3.1.amd64",
          "Debian-10:alt-openssl-0:1.1.1w-3.2.amd64",
          "Debian-10:alt-openssl-0:1.1.1w-3.4.amd64",
          "Debian-10:alt-openssl-dev-0:1.1.1w-3.1.amd64",
          "Debian-10:alt-openssl-dev-0:1.1.1w-3.2.amd64",
          "Debian-10:alt-openssl-dev-0:1.1.1w-3.4.amd64",
          "Debian-10:alt-openssl-doc-0:1.1.1w-3.1.all",
          "Debian-10:alt-openssl-doc-0:1.1.1w-3.2.all",
          "Debian-10:alt-openssl-doc-0:1.1.1w-3.4.all",
          "Debian-10:alt-openssl-libs-0:1.1.1w-3.1.amd64",
          "Debian-10:alt-openssl-libs-0:1.1.1w-3.2.amd64",
          "Debian-10:alt-openssl-libs-0:1.1.1w-3.4.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-45447"
        }
      ],
      "release_date": "2026-06-09T17:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-18T16:21:31.427831Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1781799687",
          "product_ids": [
            "Debian-10:alt-openssl-0:1.1.1w-3.5.amd64",
            "Debian-10:alt-openssl-dev-0:1.1.1w-3.5.amd64",
            "Debian-10:alt-openssl-doc-0:1.1.1w-3.5.all",
            "Debian-10:alt-openssl-libs-0:1.1.1w-3.5.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1781799687"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T17:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-10:alt-openssl-0:1.1.1w-3.1.amd64",
            "Debian-10:alt-openssl-0:1.1.1w-3.2.amd64",
            "Debian-10:alt-openssl-0:1.1.1w-3.4.amd64",
            "Debian-10:alt-openssl-dev-0:1.1.1w-3.1.amd64",
            "Debian-10:alt-openssl-dev-0:1.1.1w-3.2.amd64",
            "Debian-10:alt-openssl-dev-0:1.1.1w-3.4.amd64",
            "Debian-10:alt-openssl-doc-0:1.1.1w-3.1.all",
            "Debian-10:alt-openssl-doc-0:1.1.1w-3.2.all",
            "Debian-10:alt-openssl-doc-0:1.1.1w-3.4.all",
            "Debian-10:alt-openssl-libs-0:1.1.1w-3.1.amd64",
            "Debian-10:alt-openssl-libs-0:1.1.1w-3.2.amd64",
            "Debian-10:alt-openssl-libs-0:1.1.1w-3.4.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Debian-10:alt-openssl-0:1.1.1w-3.5.amd64",
            "Debian-10:alt-openssl-dev-0:1.1.1w-3.5.amd64",
            "Debian-10:alt-openssl-doc-0:1.1.1w-3.5.all",
            "Debian-10:alt-openssl-libs-0:1.1.1w-3.5.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}