Critical Security Flaws in Stunnel Affect Fedora 43 and 44

Critical Security Flaws in Stunnel Affect Fedora 43 and 44

First seen 16 Aug 2026, 19:52 UTC Linuxsecurity 95% similarity 70.5

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities were discovered in Stunnel, affecting Fedora versions 43 and 44. CVE-2026-70368 addresses an out-of-bounds memory access issue triggered by logging attacker-controlled messages longer than 1,024 bytes. CVE-2026-70367 fixes a SOCKS server bypass vulnerability that allows attackers to circumvent localhost filters using alternate encodings. Both vulnerabilities were published on 2026-08-04 and have been patched in the latest updates. The flaws could potentially lead to unauthorized access and escalation of privileges for affected systems. Users are advised to upgrade to the latest version to mitigate these risks. The vulnerabilities were reported by AISLE Research and Clemens Lang, highlighting the importance of regular audits of Linux privileges.

Key Points: • Two critical vulnerabilities (CVE-2026-70367 and CVE-2026-70368) fixed in Stunnel. • Affected systems include Fedora versions 43 and 44, posing risks of unauthorized access. • Users should upgrade to the latest Stunnel version to mitigate these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
CVE-2026-70368 published
An out-of-bounds memory access vulnerability was disclosed, affecting Stunnel's logging functionality.
Linuxsecurity
2026-08-04
CVE-2026-70367 published
A SOCKS server bypass vulnerability was disclosed, allowing circumvention of localhost filters.
Linuxsecurity
2026-08-16
Patches released for Fedora 43 and 44
Updates were made available to fix the critical vulnerabilities in Stunnel for both Fedora versions.
Linuxsecurity

Community

Browse all →