DEBIAN-CVE-2026-44378

Source
https://security-tracker.debian.org/tracker/CVE-2026-44378
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44378.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-44378
Upstream
  • CVE-2026-44378
Published
2026-05-27T18:16:23.470Z
Modified
2026-06-03T09:00:11.748669826Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted even in structures which are required to be encoded as DER, which prohibits indefinite length encodings. This vulnerability is fixed in 3.12.0.

References

Affected packages

Debian:13 / botan3

Package

Name
botan3
Purl
pkg:deb/debian/botan3?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.7.1+dfsg-2
3.8.1+dfsg-1
3.9.0+dfsg-1
3.9.0+dfsg-2
3.9.0+dfsg-2.1
3.10.0+dfsg-1
3.10.0+dfsg-2
3.11.0+dfsg-1
3.11.1+dfsg-1
3.11.1+dfsg-2
3.12.0+dfsg-1
3.12.0+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44378.json"

Debian:14 / botan3

Package

Name
botan3
Purl
pkg:deb/debian/botan3?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.12.0+dfsg-2

Affected versions

3.*
3.7.1+dfsg-2
3.8.1+dfsg-1
3.9.0+dfsg-1
3.9.0+dfsg-2
3.9.0+dfsg-2.1
3.10.0+dfsg-1
3.10.0+dfsg-2
3.11.0+dfsg-1
3.11.1+dfsg-1
3.11.1+dfsg-2
3.12.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44378.json"