Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94574.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94574
Upstream
Published
2026-08-04T14:16:32Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-70368 affecting package stunnel 5.74-1
Details

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".

References

Affected packages

Azure Linux:3 / stunnel

Package

Name
stunnel
Purl
pkg:rpm/azure-linux/stunnel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
5.74-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94574.json"