Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Debian 11 phpseclib TLS Confusion and Padding Oracle Attack Overview

debian lts
Calendar Grey March 30, 2026
Scroller Debian Lts
Discover vulnerabilities in phpseclib affecting TLS verification and AES-CBC implementation. Upgrade recommended now.
Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library

Summary

CVE-2023-52892

Some characters in Subject Alternative Name fields in TLS
certificates were incorrectly allowed to have a special meaning
in regular expressions, leading to name confusion in X.509
certificate host verification.

CVE-2026-32935

The AES-CBC implementation was susceptible to a padding oracle
timing attack due to the use of a short-circuiting logical
operator in the unpadding function.

For Debian 11 bullseye, these problems have been fixed in version
1.0.19-3+deb11u3.

We recommend that you upgrade your phpseclib packages.

For the detailed security status of phpseclib please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/phpseclib

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

Package: phpseclib
Version: 1.0.19-3+deb11u3
CVE ID: CVE-2023-52892 CVE-2026-32935

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.