Skip to content
Fedora 44 Stunnel Key Memory Access Fix and SOCKS Bypass CVE-2026

Fedora 44 Stunnel Key Memory Access Fix and SOCKS Bypass CVE-2026

Linuxsecurity •LinuxSecurity Advisories • August 16, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

Stunnel is a socket wrapper which can provide TLS/SSL

(Transport Layer Security/Secure Sockets Layer) support

to ordinary applications. For example, it can be used in

conjunction with imapd to create a TLS secure IMAP server.

* Security bugfixes - CVE-2026-70368: Fixed an out-of-bounds memory access triggered by logging attacker-controlled protocol messages longer than 1,024 bytes (thanks to AISLE Research and Clemens Lang). - CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost destination filter using alternate local-address encodings and interface-scoped IPv6 destinations (thanks to AISLE Research and Clemens Lang). - Restricted Windows GUI/service control pipes to local clients. * Bugfixes - Fixed concurrent DTLS handshakes from clients sharing an IP address. - Fixed version reporting in builds from source. - Rejected stream-oriented protocol negotiation with the UDP transport during configuration validation. - Fixed a TCP stream truncation (thanks to Solomon Jacobs). - Fixed a transfer() loop (thanks to Solomon Jacobs). - Fixed log reopening logs without a configured log file. - Fixed some logged values (thanks to Jose Alf.). - Fixed some e...

* Fri Aug 7 2026 Clemens Lang - 5.80-1 - New upstream release 5.80

* Fri Aug 7 2026 Clemens Lang - 5.80-1 - New upstream release 5.80

[ 1 ] Bug #2494485 - stunnel-5.80 is available

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-67c2201ad8' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities