Source: open62541 Version: 1.4.11.1-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for open62541. CVE-2026-15690[0]: | A vulnerability was identified in open62541 up to 1.5.5. Affected by | this issue is the function responseReadNamespacesArray of the file | src/client/ua_client_connect.c of the component Shared Client | Library. Such manipulation of the argument Server_NamespaceArray | leads to null pointer dereference. The attack can be executed | remotely. The attack requires a high level of complexity. The | exploitation is known to be difficult. The exploit is publicly | available and might be used. The project closed the issue report, | stating that this is not the official way to report a security | vulnerability. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15690 https://www.cve.org/CVERecord?id=CVE-2026-15690 [1] https://github.com/open62541/open62541/issues/8104 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

