CTRL-OS Security Tracker
This is the security tracker for CTRL-OS. It allows monitoring the status of vulnerabilities that affect CTRL-OS releases. Vulnerabilities are ingested from official sources, such as NVD and others.
For general information about installing or upgrading CTRL-OS, refer to the documentation. We are eager to hear your feedback and suggestions for this security tracker. Channels to reach us are documented here.
Releases
These are the currently supported releases.
Latest Events
GLIBC-SA-2026-0013
CTRL-OS 26.05
glibc
Potential stack-based buffer clash during tilde expansion in wordexp
2026-08-25 17:43 CEST
Plausible → In Progress
GLIBC-SA-2026-0014
CTRL-OS 26.05
glibc
wordexp with WRDE_APPEND may result in an invalid call to free()
2026-08-25 17:43 CEST
Plausible → In Progress
GLIBC-SA-2026-0011
CTRL-OS 26.05
glibc
Potential buffer overflow in ns_sprintrrf TSIG handling path
2026-08-25 17:42 CEST
In Progress → Resolved
GLIBC-SA-2026-0012
CTRL-OS 26.05
glibc
Buffer overread in ns_printrrf with corrupted RDATA field
2026-08-25 17:42 CEST
In Progress → Resolved
CVE-2026-14457
CTRL-OS 26.05
openssl_3_5, openssl_3_6, openssl_4_0
RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-18798
CTRL-OS 26.05
openssl_3_5, openssl_3_6, openssl_4_0
QUIC Server May Trigger Double Free When Processing INITIAL Packet
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-54874
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
Excessive Memory Use Buffering DTLS Records for a Future Epoch
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-63072
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
Heap Buffer Overflow in CMS Key Unwrapping
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-63073
CTRL-OS 26.05
openssl_3_5, openssl_3_6, openssl_4_0
Untrusted Sender DN Used as Format String in CMP Response Validation
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-63074
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
CMP Indefinite Cache Growth of ExtraCerts
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-63075
CTRL-OS 26.05
openssl_3_5, openssl_3_6, openssl_4_0
QUIC ACK-only Packet Retention Can Cause Memory Exhaustion
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-63076
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-75803
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
2026-08-25 17:38 CEST
New → Plausible
CVE-2026-14457
CTRL-OS 26.05
openssl_3_5, openssl_3_6, openssl_4_0
RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate
2026-08-25 17:36 CEST
New
CVE-2026-18798
CTRL-OS 26.05
openssl_3_5, openssl_3_6, openssl_4_0
QUIC Server May Trigger Double Free When Processing INITIAL Packet
2026-08-25 17:36 CEST
New
CVE-2026-54874
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
Excessive Memory Use Buffering DTLS Records for a Future Epoch
2026-08-25 17:36 CEST
New
CVE-2026-63072
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
Heap Buffer Overflow in CMS Key Unwrapping
2026-08-25 17:36 CEST
New
CVE-2026-63073
CTRL-OS 26.05
openssl_3_5, openssl_3_6, openssl_4_0
Untrusted Sender DN Used as Format String in CMP Response Validation
2026-08-25 17:36 CEST
New
CVE-2026-63074
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
CMP Indefinite Cache Growth of ExtraCerts
2026-08-25 17:36 CEST
New
CVE-2026-63075
CTRL-OS 26.05
openssl_3_5, openssl_3_6, openssl_4_0
QUIC ACK-only Packet Retention Can Cause Memory Exhaustion
2026-08-25 17:36 CEST
New
CVE-2026-63076
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
2026-08-25 17:36 CEST
New
CVE-2026-75803
CTRL-OS 26.05
openssl_3, openssl_3_5, openssl_3_6, openssl_4_0
AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
2026-08-25 17:34 CEST
New
GHSA-p58j-h3vm-3fp5
CTRL-OS 26.05
libheif
Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image)
2026-08-25 14:41 CEST
New → Plausible
GHSA-j264-xvrp-5v7q
CTRL-OS 26.05
libheif
Out-of-bounds Write in libheif
2026-08-25 14:41 CEST
New → Plausible
GHSA-2jg2-4ch7-h545
CTRL-OS 26.05
libheif
Remote Code Execution: Out-of-bounds read and write in derived-item and pixel-plane handling
2026-08-25 14:41 CEST
New → Plausible
GHSA-g89c-p67h-r497
CTRL-OS 26.05
libheif
Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items
2026-08-25 14:41 CEST
New → Plausible
GHSA-24wx-9w62-c96w
CTRL-OS 26.05
libheif
Security report: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS
2026-08-25 14:41 CEST
New → Plausible
GHSA-xw34-mjcp-jqh8
CTRL-OS 26.05
libheif
Security report: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames
2026-08-25 14:41 CEST
New → Plausible
GHSA-x8xm-cm2c-cfc8
CTRL-OS 26.05
libheif
Security report: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS
2026-08-25 14:41 CEST
New → Plausible
GHSA-p58j-h3vm-3fp5
CTRL-OS 26.05
libheif
Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image)
2026-08-25 14:40 CEST
New