DSA-6412-1 botan3 - security update
Multiple security issues were discovered in Botan, a C++ cryptography library, which could result in denial of service, certificate validation bypass or authentication bypass. These issues have been addressed by updating botan3 to the new upstream release 3.12.0. As a consequence this update changes the SONAME of the shared library, and the runtime library package is renamed from libbotan-3-7 to libbotan-3-12. No package in the stable distribution links against the library, so no other packages in trixie are affected by this change. The libbotan-3-7 package is no longer built and will not be removed automatically on upgrade if it had been installed manually. Locally built or third-party software linking against libbotan-3-7 needs to be rebuilt against libbotan-3-12, after which the old library package can be removed. https://security-tracker.debian.org/tracker/DSA-6412-1
CSIRTS triage
- What
- Multiple security issues in Botan cryptography library including denial of service and certificate/authentication bypass.
- Who is affected
- Systems running Botan versions prior to 3.12.0 in Debian stable distribution.
- Urgency
- Moderate; library has been updated but requires rebuild of dependent software.
- Action
- Upgrade to Botan 3.12.0 and rebuild any locally built or third-party software linking against the old libbotan-3-7 library.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Botan
Get an email when a new Botan advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00323.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-443780.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-44378 | coverage & exploitation status | NVD · CVE.org |
More from Debian Security Advisories
- unknownDSA-6485-1 tryton-server - security update2026-09-06
- unknownDSA-6486-1 libde265 - security update2026-09-06
- unknownDSA-6484-1 chromium - security update2026-09-05
- unknownDSA-6483-1 thunderbird - security update2026-09-04
- unknownDSA-6482-1 chromium - security update2026-09-03