rpm package
opensuse/s2n&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/s2n&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-16318 | Med | 5.3 | < 1.7.7-1.1 | 1.7.7-1.1 | Jul 21, 2026 | The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second cal | |
| CVE-2026-16317 | Med | 6.5 | < 1.7.7-1.1 | 1.7.7-1.1 | Jul 21, 2026 | Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer co |
- affected < 1.7.7-1.1fixed 1.7.7-1.1
The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second cal
- affected < 1.7.7-1.1fixed 1.7.7-1.1
Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer co