1sealsemantic last-mile verification

Research / Advisories

Advisories

Vulnerabilities 1seal found, reported and wrote up in full. Each write-up keeps its original date and wording; dated updates are marked.

10 advisories, newest first by original publication. Summaries reviewed 2026-09-25 against the records each write-up links. Source assessments remain separate; different CVSS versions are not a revision of one another.

  1. 1SEAL-2026-011 Published Updated

    Linux Bluetooth: pairing without MITM protection

    Conditions
    Legacy Bluetooth pairing can satisfy BT_SECURITY_HIGH without authenticated MITM protection.
    What to do
    Check your kernel vendor's backports for both linked commits. A mainline fix does not establish the state of your distribution.
    Fix and severity by source
    • 1seal severity 7.1 · CVSS 3.1 Fix / version: mainline commits d05111bfe37b and 20756fec2f01
    • CVE-2026-31773 severity 8.8 · CVSS 3.1 Fix / version: Linux 7.0; stable backports listed in the CNA record; mainline 20756fec2f01
    • CVE-2026-43334 severity 8.8 · CVSS 3.1 Fix / version: Linux 7.0; stable backports listed in the CNA record; mainline d05111bfe37b

    Current evidence for Linux Bluetooth: pairing without MITM protection

  2. 1SEAL-2026-010 Published Updated

    UEFI firmware parser: Tiano buffer writes

    Conditions
    Parsing an untrusted firmware image can reach out-of-bounds writes in MakeTable or ReadCLen.
    What to do
    Check the installed package for the linked Tiano bounds checks. Release metadata conflicts: CVE records name 1.14; repository advisories name 1.13. Do not resolve that discrepancy from the version number alone.
    Fix and severity by source
    • 1seal severity Critical · no score Fix / version: CVE records: 1.14; repository GHSAs: 1.13 (conflicting version metadata)
    • CVE-2026-54333 severity 9.8 · CVSS 3.1 Fix / version: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
    • CVE-2026-54334 severity 9.8 · CVSS 3.1 Fix / version: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)

    Current evidence: ReadCLen heap write · MakeTable stack write

  3. 1SEAL-2026-009 Published

    OpenSSL: unauthorized OCSP responders

    Conditions
    OpenSSL 3.6 stapled OCSP verification can accept a response from an unauthorized certificate supplied in the peer chain.
    What to do
    Check that your build includes the recorded master or openssl-3.6 fix. A released version is not established by this write-up; PR #30323 itself was closed without merge.
    Fix and severity by source
    • 1seal severity High · no score Fix / version: master and openssl-3.6 fixes published

    Current evidence for OpenSSL: unauthorized OCSP responders

  4. 1SEAL-2026-007 Published

    Telegram iOS: TL parsing over-read

    Conditions
    Malformed TL data reaches a bounds check whose operator precedence permits a heap buffer over-read.
    What to do
    Use a version containing the release-12.4 bounds-check correction. The source-branch evidence does not verify rollout to every installed app.
    Fix and severity by source
    • 1seal severity 5.3 · CVSS 3.1 Fix / version: release-12.4

    Current evidence for Telegram iOS: TL parsing over-read

  5. 1SEAL-2026-006 Published

    BuildKit: ContainerID path escape

    Conditions
    An attacker-controlled gateway frontend on a runc worker can use ContainerID paths to escape the executor root.
    What to do
    Upgrade affected BuildKit deployments to v0.28.1 or later; check that the worker actually runs the updated binary.
    Fix and severity by source
    • 1seal severity 8.4 · CVSS 3.1 Fix / version: v0.28.1+
    • CVE-2026-33747 severity 8.4 · CVSS 3.1 Fix / version: v0.28.1+

    Current evidence for BuildKit: ContainerID path escape

  6. 1SEAL-2026-002 Published

    AWS-LC: CommonName constraint bypasses

    Conditions
    A wildcard or Unicode CommonName can bypass name constraints when hostname verification falls back to CN without a DNS name SAN.
    What to do
    Check the package-specific AWS advisories for fixed versions. Disabling CN fallback avoids this path; do not apply the AWS-LC version number to aws-lc-sys.
    Fix and severity by source
    • 1seal severity 7.4 · CVSS 3.1 Fix / version: AWS advisories: AWS-LC 1.71.0; aws-lc-sys 0.39.0
    • GHSA-394x-vwmw-crm3 severity Moderate · no score Fix / version: aws-lc-sys 0.39.0
    • GHSA-3jrg-j22w-mpmc severity Moderate · no score Fix / version: AWS-LC 1.71.0

    Current evidence: wildcard CommonName constraint bypass · Unicode CommonName constraint bypass

  7. 1SEAL-2026-003 Published

    Tekton: git resolver path traversal

    Conditions
    A tenant able to create requests using the git resolver can read files accessible to the resolver pod, including its credentials.
    What to do
    Use the listed patched release for your branch. Until updated, restrict access to the git resolver and reduce its service-account permissions. The upstream broad affected range overlaps its own patched list.
    Fix and severity by source
    • 1seal severity 9.6 · CVSS 3.1 Fix / version: v1.0.1, v1.3.3, v1.6.1, v1.9.2, v1.10.2
    • CVE-2026-33211 severity 9.6 · CVSS 3.1 Fix / version: v1.0.1, v1.3.3, v1.6.1, v1.9.2, v1.10.2

    Current evidence for Tekton: git resolver path traversal

  8. 1SEAL-2026-005 Published

    Ledger Bitcoin app: Merkle binding bypass

    Conditions
    A malicious host interacting with the signing flow can bypass a reported Merkle preimage integrity check.
    What to do
    Check for the recorded commit in the app build you use. No fixed app release is recorded here; a code fix is not proof that your device has received it.
    Fix and severity by source
    • 1seal severity High · no score Fix / version: commit 0586ab2

    Current evidence for Ledger Bitcoin app: Merkle binding bypass

  9. 1SEAL-2026-001 Published Updated

    AWS event-stream: decoder buffer write

    Conditions
    A client processing attacker-controlled event-stream headers can reach an out-of-bounds write in the streaming decoder.
    What to do
    Upgrade aws-c-event-stream to v0.6.0 or later and affected AWS SDK for C++ builds to the vendor's fixed version below. Check lock files as well: the AWS Common Runtime can pin an older version as a transitive dependency.
    Fix and severity by source
    • 1seal severity 8.1 · CVSS 3.1 Fix / version: v0.6.0
    • CVE-2026-5190 severity 7.7 · CVSS 4.0 Fix / version: aws-c-event-stream 0.6.0; aws-sdk-cpp 1.11.764

    Current evidence for AWS event-stream: decoder buffer write

Every public record, including CVEs, GHSAs and fixes without a 1seal write-up, is in the research record. How we report and publish: disclosure policy.