UBUNTU-CVE-2026-11999

Source
https://ubuntu.com/security/CVE-2026-11999
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11999.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-11999
Upstream
Published
2026-06-25T18:16:00Z
Modified
2026-06-29T23:15:17Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra whose application calls X509_verify_cert() with caller-supplied untrusted intermediates; for those users it is critical, otherwise the library is unaffected. Native wolfSSL TLS/DTLS usage is not impacted. X509_verify_cert() returned success based only on the last verified link rather than on reaching a trust anchor: when the supplied chain is deeper than the verifier's maximum path depth (default 100), path building runs out of depth while still walking untrusted intermediates and the chain is accepted even though it never reaches a configured trust anchor, allowing acceptance of an attacker-controlled certificate. The default TLS handshake (WOLFSSL_VERIFY_PEER) is not affected; only applications doing manual or deferred verification through this API are.

References

Affected packages

Ubuntu:16.04:LTS
wolfssl

Package

Name
wolfssl
Purl
pkg:deb/ubuntu/wolfssl?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4.8+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libcyassl5",
            "binary_version": "3.4.8+dfsg-1"
        },
        {
            "binary_name": "libwolfssl0",
            "binary_version": "3.4.8+dfsg-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11999.json"
Ubuntu:18.04:LTS
wolfssl

Package

Name
wolfssl
Purl
pkg:deb/ubuntu/wolfssl?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.10.2+dfsg-2
3.12.0+dfsg-1
3.12.2+dfsg-1
3.13.0+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libwolfssl15",
            "binary_version": "3.13.0+dfsg-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11999.json"
Ubuntu:20.04:LTS
wolfssl

Package

Name
wolfssl
Purl
pkg:deb/ubuntu/wolfssl?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.1.0+dfsg-2
4.2.0+dfsg-1
4.2.0+dfsg-2
4.2.0+dfsg-3
4.3.0+dfsg-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libwolfssl24",
            "binary_version": "4.3.0+dfsg-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11999.json"
Ubuntu:22.04:LTS
wolfssl

Package

Name
wolfssl
Purl
pkg:deb/ubuntu/wolfssl?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.6.0-3
5.*
5.0.0-1
5.1.1-1
5.2.0-1
5.2.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libwolfssl32",
            "binary_version": "5.2.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11999.json"
Ubuntu:24.04:LTS
wolfssl

Package

Name
wolfssl
Purl
pkg:deb/ubuntu/wolfssl?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.5.4-2
5.5.4-2.1
5.6.4-2
5.6.6-1.2
5.6.6-1.3
5.6.6-1.3build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libwolfssl42t64",
            "binary_version": "5.6.6-1.3build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11999.json"
Ubuntu:25.10
wolfssl

Package

Name
wolfssl
Purl
pkg:deb/ubuntu/wolfssl?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.7.2-0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libwolfssl42t64",
            "binary_version": "5.7.2-0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11999.json"
Ubuntu:26.04:LTS
wolfssl

Package

Name
wolfssl
Purl
pkg:deb/ubuntu/wolfssl?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.7.2-0.1
5.8.2-1.2
5.8.4-1
5.9.1-0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libwolfssl44",
            "binary_version": "5.9.1-0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11999.json"