{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/vex/2026/cve-2026-63074-els_os-debian11els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-17T12:47:48Z",
      "generator": {
        "date": "2026-09-17T12:47:48Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-63074-ELS_OS-DEBIAN11ELS",
      "initial_release_date": "2026-08-25T13:19:00Z",
      "revision_history": [
        {
          "date": "2026-08-25T13:19:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-17T12:47:48Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-63074"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                "product": {
                  "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_id": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                "product": {
                  "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_id": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                "product": {
                  "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_id": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                "product": {
                  "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_id": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                "product": {
                  "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_id": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                "product": {
                  "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_id": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                "product": {
                  "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_id": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                "product": {
                  "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_id": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                "product": {
                  "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_id": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
                "product": {
                  "name": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
                  "product_id": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-doc@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64"
        },
        "product_reference": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64"
        },
        "product_reference": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
        },
        "product_reference": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64"
        },
        "product_reference": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64"
        },
        "product_reference": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
        },
        "product_reference": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all"
        },
        "product_reference": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64"
        },
        "product_reference": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
        },
        "product_reference": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64"
        },
        "product_reference": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-63074",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
          "title": "Vulnerability description"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
          "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
          "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
          "Debian-11:libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
          "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
          "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
          "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
          "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
          "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
          "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-63074"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7",
          "url": "https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f",
          "url": "https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46",
          "url": "https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af",
          "url": "https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a",
          "url": "https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260825.txt",
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        }
      ],
      "release_date": "2026-08-25T13:19:00Z",
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        },
        {
          "category": "impact",
          "date": "2026-09-15T10:35:54.598040Z",
          "details": "unknown",
          "product_ids": [
            "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
            "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
            "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
            "Debian-11:libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
            "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
            "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
            "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
            "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
            "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
            "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
          ]
        }
      ]
    }
  ]
}