The Slackware Linux Security Team released stunnel version 5.80 for both Slackware 15.0 and the development branch to address two critical vulnerabilities. The first patch resolves an out-of-bounds memory access flaw that activates when logging attacker-controlled protocol messages exceeding 1,024 bytes. The second update closes a SOCKS server mode bypass that allowed attackers to route traffic through alternate local-address encodings and interface-scoped IPv6 destinations.
stunnel (SSA:2026-216-01)
stunnel (SSA:2026-216-01)
stunnel (SSA:2026-216-01)
stunnel (SSA:2026-216-01)
New stunnel packages are available for Slackware 15.0 and -current to
fix security issues.
Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/stunnel-5.80-i586-1_slack15.0.txz: Upgraded.
This update fixes security issues:
Fixed an out-of-bounds memory access triggered by logging attacker-
controlled protocol messages longer than 1,024 bytes.
Fixed a SOCKS server mode bypass of the localhost destination filter
using alternate local-address encodings and interface-scoped IPv6
destinations.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-70368
https://www.cve.org/CVERecord?id=CVE-2026-70367
(* Security fix *)
+--------------------------+
Where to find the new packages:
+-----------------------------+
Thanks to the friendly folks at the OSU Open Source Lab
( http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.
Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/stunnel-5.80-i586-1_slack15.0.txz
Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/stunnel-5.80-x86_64-1_slack15.0.txz
Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/stunnel-5.80-i686-1.txz
Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/stunnel-5.80-x86_64-1.txz
MD5 signatures:
+-------------+
Slackware 15.0 package:
4a8e5ceaa4595573e7394d49aa27d498 stunnel-5.80-i586-1_slack15.0.txz
Slackware x86_64 15.0 package:
bcb891631379c3c048ef79464c909ebf stunnel-5.80-x86_64-1_slack15.0.txz
Slackware -current package:
e02f336c2e7c5d81d5c448bdeb54b5ba n/stunnel-5.80-i686-1.txz
Slackware x86_64 -current package:
95a10a00c3ace85bfa137886931459fb n/stunnel-5.80-x86_64-1.txz
Installation instructions:
+------------------------+
Upgrade the package as root:
# upgradepkg stunnel-5.80-i586-1_slack15.0.txz
+-----+
Slackware Linux Security Team
http://slackware.com/gpg-key