{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/vex/2026/cve-2026-63076-els_os-debian11els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-17T12:47:48Z",
      "generator": {
        "date": "2026-09-17T12:47:48Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-63076-ELS_OS-DEBIAN11ELS",
      "initial_release_date": "2026-08-25T13:19:00Z",
      "revision_history": [
        {
          "date": "2026-08-25T13:19:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-17T12:47:48Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-63076"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                "product": {
                  "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_id": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                "product": {
                  "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_id": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                "product": {
                  "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_id": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                "product": {
                  "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_id": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                "product": {
                  "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_id": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                "product": {
                  "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_id": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                "product": {
                  "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_id": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/openssl@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                "product": {
                  "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_id": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl1.1@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                "product": {
                  "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_id": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-dev@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
                "product": {
                  "name": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
                  "product_id": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssl-doc@1.1.1w-0%2Bdeb11u8%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64"
        },
        "product_reference": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64"
        },
        "product_reference": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
        },
        "product_reference": "openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64"
        },
        "product_reference": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64"
        },
        "product_reference": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
        },
        "product_reference": "libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all"
        },
        "product_reference": "libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64"
        },
        "product_reference": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
        },
        "product_reference": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64"
        },
        "product_reference": "libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-63076",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
          "title": "Vulnerability description"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
          "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
          "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
          "Debian-11:libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
          "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
          "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
          "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
          "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
          "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
          "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-63076"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b",
          "url": "https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e",
          "url": "https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259",
          "url": "https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226",
          "url": "https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c",
          "url": "https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260825.txt",
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        }
      ],
      "release_date": "2026-08-25T13:19:00Z",
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        },
        {
          "category": "impact",
          "date": "2026-09-15T10:35:52.049559Z",
          "details": "unknown",
          "product_ids": [
            "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
            "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
            "Debian-11:libssl-dev-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
            "Debian-11:libssl-doc-0:1.1.1w-0+deb11u8+tuxcare.els1.all",
            "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
            "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
            "Debian-11:libssl1.1-0:1.1.1w-0+deb11u8+tuxcare.els1.armel",
            "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.amd64",
            "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.arm64",
            "Debian-11:openssl-0:1.1.1w-0+deb11u8+tuxcare.els1.armel"
          ]
        }
      ]
    }
  ]
}