DEBIAN-CVE-2026-42327

Source
https://security-tracker.debian.org/tracker/CVE-2026-42327
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42327.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-42327
Upstream
Published
2026-05-14T21:16:45.430Z
Modified
2026-05-15T14:00:09.131160365Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocspresponders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::fromutf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant — resulting in undefined behavior. This vulnerability is fixed in 0.10.79.

References

Affected packages

Debian:11 / rust-openssl

Package

Name
rust-openssl
Purl
pkg:deb/debian/rust-openssl?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.10.29-1
0.10.29-1+deb11u1
0.10.36-1
0.10.41-1
0.10.45-1
0.10.57-1
0.10.64-1
0.10.68-1
0.10.70-1
0.10.72-1
0.10.73-1
0.10.78-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42327.json"

Debian:12 / rust-openssl

Package

Name
rust-openssl
Purl
pkg:deb/debian/rust-openssl?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.10.45-1
0.10.57-1
0.10.64-1
0.10.68-1
0.10.70-1
0.10.72-1
0.10.73-1
0.10.78-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42327.json"

Debian:13 / rust-openssl

Package

Name
rust-openssl
Purl
pkg:deb/debian/rust-openssl?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.10.72-1
0.10.73-1
0.10.78-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42327.json"

Debian:14 / rust-openssl

Package

Name
rust-openssl
Purl
pkg:deb/debian/rust-openssl?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.10.72-1
0.10.73-1
0.10.78-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42327.json"