Linuxsecurity Critical Security Flaws in Stunnel Affect Fedora 43 and 44
Article Content
- •Two critical vulnerabilities (CVE-2026-70367 and CVE-2026-70368) fixed in Stunnel.
- •Affected systems include Fedora versions 43 and 44, posing risks of unauthorized access.
- •Users should upgrade to the latest Stunnel version to mitigate these vulnerabilities.
Two critical vulnerabilities were discovered in Stunnel, affecting Fedora versions 43 and 44. CVE-2026-70368 addresses an out-of-bounds memory access issue triggered by logging attacker-controlled messages longer than 1,024 bytes. CVE-2026-70367 fixes a SOCKS server bypass vulnerability that allows attackers to circumvent localhost filters using alternate encodings. Both vulnerabilities were published on 2026-08-04 and have been patched in the latest updates. The flaws could potentially lead to unauthorized access and escalation of privileges for affected systems. Users are advised to upgrade to the latest version to mitigate these risks. The vulnerabilities were reported by AISLE Research and Clemens Lang, highlighting the importance of regular audits of Linux privileges.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-70367 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed