This bug was fixed in the package opencryptoki - 3.23.0+dfsg-0ubuntu3.1
---------------
opencryptoki (3.23.0+dfsg-0ubuntu3.1) noble-security; urgency=medium
* d/p/lp-2163181-cca-adjust-host-library-version-detection.patch: Fix
CCA host library version detection for newer CCA versions, needed to
support CCA 8.4; without it, the CCA host library version is reported
as invalid. (LP: #2163181)
* d/p/lp-2163253-fix-ber-der-decoder-out-of-bounds-access.patch: Fix
possible out-of-bounds access in BER decode functions. (LP: #2163253)
(CVE-2026-40253)
* d/p/lp-2163254-fix-symlink-following-vulnerabilities.patch: Fix
symlink-following vulnerabilities (CWE-59). (LP: #2163254)
(CVE-2026-23893)
-- Frank Heimes <[email protected]> Tue, 18 Aug 2026 15:24:04
+0000
** Changed in: opencryptoki (Ubuntu Noble)
Status: Triaged => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-23893
** CVE added: https://cve.org/CVERecord?id=CVE-2026-40253
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163181
Title:
[UBUNTU 24.04] openCryptoki: Fix for supporting CCA 8.4
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu-z-systems/+bug/2163181/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs