USN-8571-2: Apache HTTP Server regression
USN-8571-2
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCryptoki incorrectly handled symlinks. An attacker in the token-group could possibly use this issue to achieve privilege escalation or access sensitive information. (CVE-2026-23893)
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
The publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.