Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian 11 phpseclib TLS Confusion and Padding Oracle Attack Overview

debian lts
Calendar Grey March 30, 2026
Dist Debian Esm H88
Discover vulnerabilities in phpseclib affecting TLS verification and AES-CBC implementation. Upgrade recommended now.
Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library

Summary

CVE-2023-52892

Some characters in Subject Alternative Name fields in TLS
certificates were incorrectly allowed to have a special meaning
in regular expressions, leading to name confusion in X.509
certificate host verification.

CVE-2026-32935

The AES-CBC implementation was susceptible to a padding oracle
timing attack due to the use of a short-circuiting logical
operator in the unpadding function.

For Debian 11 bullseye, these problems have been fixed in version
1.0.19-3+deb11u3.

We recommend that you upgrade your phpseclib packages.

For the detailed security status of phpseclib please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/phpseclib

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

Package: phpseclib
Version: 1.0.19-3+deb11u3
CVE ID: CVE-2023-52892 CVE-2026-32935

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here