Debian 13 — cjose — vulnerability — patch and remediation guide
🟢 Low ⏱ 5–15 min Last verified: 1 December 2025 Affected versions: Debian 13 📖 ~4 min read • Source: Debian Security Tracker Related CVEs: CVE-2023-37464 Upstream summary: OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual […]