This bug was fixed in the package opencryptoki - 3.23.0+dfsg-0ubuntu3.1

---------------
opencryptoki (3.23.0+dfsg-0ubuntu3.1) noble-security; urgency=medium

  * d/p/lp-2163181-cca-adjust-host-library-version-detection.patch: Fix
    CCA host library version detection for newer CCA versions, needed to
    support CCA 8.4; without it, the CCA host library version is reported
    as invalid. (LP: #2163181)
  * d/p/lp-2163253-fix-ber-der-decoder-out-of-bounds-access.patch: Fix
    possible out-of-bounds access in BER decode functions. (LP: #2163253)
    (CVE-2026-40253)
  * d/p/lp-2163254-fix-symlink-following-vulnerabilities.patch: Fix
    symlink-following vulnerabilities (CWE-59). (LP: #2163254)
    (CVE-2026-23893)

 -- Frank Heimes <[email protected]>  Tue, 18 Aug 2026 15:24:04
+0000

** Changed in: opencryptoki (Ubuntu Noble)
       Status: Triaged => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-23893

** CVE added: https://cve.org/CVERecord?id=CVE-2026-40253

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163181

Title:
  [UBUNTU 24.04] openCryptoki: Fix for supporting CCA 8.4

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu-z-systems/+bug/2163181/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to