DEBIAN-CVE-2026-4541

Source
https://security-tracker.debian.org/tracker/CVE-2026-4541
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4541.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-4541
Upstream
Published
2026-03-22T09:15:59Z
Modified
2026-09-14T17:03:13Z
Severity
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes improper verification of cryptographic signature. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is considered difficult. The exploit has been published and may be used. Upgrading to version 20260301 is recommended to address this issue. Patch name: 9c87269607e0d7d20174df742accc49c042cff17. Upgrading the affected component is recommended.

References

Affected packages

Debian:13 / tinyssh

Package

Name
tinyssh
Purl
pkg:deb/debian/tinyssh?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
20250501-1
20250501-2
20260301-1
20260401-1
20260601-1
20260906-1

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4541.json"

Debian:14 / tinyssh

Package

Name
tinyssh
Purl
pkg:deb/debian/tinyssh?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20260301-1

Affected versions

Other
20250501-1
20250501-2

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4541.json"