[From nobody Mon May  4 00:05:11 2026
Received: (at 1124407-close) by bugs.debian.org; 3 May 2026 23:02:40 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-113.1 required=4.0 tests=BAYES_00,DKIM_SIGNED,
 DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,
 MD5_SHA1_SUM,PGPSIGNATURE,RCVD_IN_DNSWL_MED,SPF_HELO_PASS,SPF_PASS,
 USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 90; hammy, 150; neutral, 152; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from mitropoulos.debian.org
 ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:37568)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wJfpg-005jwJ-2j for 1124407-close@bugs.debian.org;
 Sun, 03 May 2026 23:02:40 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by mitropoulos.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wJfpf-002OCp-0D for 1124407-close@bugs.debian.org;
 Sun, 03 May 2026 23:02:39 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=UvWTK1LO1DuaIXqGXiwo3zt9yVh9SDUpd3iakbPySy8=; b=aIykf6FRRx4mjIfmqPV/eetzuZ
 JFKiINtMDZU7xlmd4TYm94r7Xf14ZUzdZnnr7+ra5Uikd143Oa8ONg5dKBFXvVPjY0JWTMTVIHTk/
 cIJONSzM4xrPyGQ83IxZPlq+miV6KgbuwCB9F8OFAD+UMk0VizNFBxTGX0cuN76Q0tRM3FTGBMPbS
 UnENn0nBli1IhcPoOGCsOevc3pjwMYxDzErx/acQhZv+jwSc3mrOjtLRvraWoEhVwnVAOwHd6J4P9
 BIrUmwFw/Ya59qUtFlMTzGqeQwQbhNq70ohEEYi7ZneAcTT5Xjl6I4q1ervZf3z6gmNSdG1mSD2xx
 t0Otp8rg==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wJfpd-0000000ArBr-3d5X; Sun, 03 May 2026 23:02:37 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Thorsten Alteholz &lt;debian@alteholz.de&gt;
To: 1124407-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: libcoap3
Debian: DAK
Debian-Changes: libcoap3_4.3.4-1.1+deb13u3_source.changes
Debian-Source: libcoap3
Debian-Version: 4.3.4-1.1+deb13u3
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1124407: fixed in libcoap3 4.3.4-1.1+deb13u3
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============4330607767444409616==&quot;
Message-Id: &lt;E1wJfpd-0000000ArBr-3d5X@fasolo.debian.org&gt;
Date: Sun, 03 May 2026 23:02:37 +0000

--===============4330607767444409616==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: libcoap3
Source-Version: 4.3.4-1.1+deb13u3
Done: Thorsten Alteholz &lt;debian@alteholz.de&gt;

We believe that the bug you reported is fixed in the latest version of
libcoap3, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1124407@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thorsten Alteholz &lt;debian@alteholz.de&gt; (supplier of updated libcoap3 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 19 Apr 2026 10:23:22 +0200
Source: libcoap3
Architecture: source
Version: 4.3.4-1.1+deb13u3
Distribution: trixie
Urgency: medium
Maintainer: Debian IoT Maintainers &lt;debian-iot-maintainers@lists.alioth.debia=
n.org&gt;
Changed-By: Thorsten Alteholz &lt;debian@alteholz.de&gt;
Closes: 1124407 1134340
Changes:
 libcoap3 (4.3.4-1.1+deb13u3) trixie; urgency=3Dmedium
 .
   * CVE-2026-29013 (Closes: #1134340)
     fix out-of-bounds read
   * CVE-2025-34468 (Closes: #1124407)
     fix stack-based buffer overflow
Checksums-Sha1:
 2979f23db91099c1bda99e7de5cd943288e1f351 2421 libcoap3_4.3.4-1.1+deb13u3.dsc
 b013aae51d438d6c79773a324dd6c66bc8fa8614 528071 libcoap3_4.3.4.orig.tar.bz2
 7323763e407158f27101efdf3b23116539237070 14272 libcoap3_4.3.4-1.1+deb13u3.de=
bian.tar.xz
 a9f421287ee4cec56d57e404091188af364adae0 11249 libcoap3_4.3.4-1.1+deb13u3_am=
d64.buildinfo
Checksums-Sha256:
 621cfbb0acbc343c621c62565d74cbbd12c53d1c839a6cb0acf5fe225a73d7de 2421 libcoa=
p3_4.3.4-1.1+deb13u3.dsc
 a5abadd4b1e9a97c46197451326aa206c035362f0f15e7f4bb8846d7b8fcfb65 528071 libc=
oap3_4.3.4.orig.tar.bz2
 4c225353780fe616013c67bd65307c08aa0d423111520cbad1f89596b32ba471 14272 libco=
ap3_4.3.4-1.1+deb13u3.debian.tar.xz
 231182a7bef460bd7a38aa4e110d49a75f3601fe153761c47c2f7a47683ab408 11249 libco=
ap3_4.3.4-1.1+deb13u3_amd64.buildinfo
Files:
 1520b6a2ec58b919f836db702177aebd 2421 libs optional libcoap3_4.3.4-1.1+deb13=
u3.dsc
 69a0afa3a2af381a45af7ea379220468 528071 libs optional libcoap3_4.3.4.orig.ta=
r.bz2
 86e0994cbce4e058dcdece3ce54c8d4b 14272 libs optional libcoap3_4.3.4-1.1+deb1=
3u3.debian.tar.xz
 b65ac245cad6a85a64295636249d323e 11249 libs optional libcoap3_4.3.4-1.1+deb1=
3u3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmn3ilBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYRx8XD/0d/43UlyV4o/1rkOSuUNC6M4XIPybM
YEePzSmEqGJLfcdqpeCWskvBkZNIkA70JOYrP7xqpmxJVhZ28r/L7o2V6pwudeBy
0zTk23N16ELtiYVzdSvfbQ5QgnWob75Ky7E/K5MNQvDI+bsydzWd4lAtxoHDAJqZ
Gk2j0mIGCc1ezEvjSXsRQhN1bk6SBXmNUEtk0x+18xp0yJB/THGHmtCmx7ddS7fK
CJyt/YDZuekM3XvxHRva21pwshA4ipHN5INiQugdkiAJvfziWtBzMAbH88mygWqq
1IQFAkgQTT8VCQr/Lj0gs4uuyapyhOq5XGF/R0CmPLMeTaMCCt5DmHzEt63JTKTf
0ZPiC1NXV22gSS5hHHiZakuJkF5DiB5YZO7GmPltIMtf7rcv9ehcEJe/khyPw0XE
T3AzB5Usnq7UL7+dzYZqQ2OXi1YxIr3Nilg6Q0M8+KbmQjq0k4uYQPk6b+xnzWCB
+erW/Ok/aXUBpwaz+to0KuE52ReUg9I/SbzNr27RM6sdJgvFy0+IZCbJ7EfovuuG
G9jkkgY729+YoBI9oRacTtmPUDegLbhg0CfLch/AXZ6FoIViAiK3yhFanV8b1oZ8
9G2+IbMQa2SrsUOU/voAefZk42anR5j6jpg0s1fvJzGJ6tC3GKifrcMV6XeMdFuQ
WOI7yzwXquobKg=3D=3D
=3DohU8
-----END PGP SIGNATURE-----


--===============4330607767444409616==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaffUDQAKCRCb9qggYcy5
IZFcAQDa1irbYXxgHmGz9fbJi1FHGxqBbGPuJIsAvWFAJaDkXQEAnyMdq0EhJLH5
fOES/l4KVXwP9QYquE1Skf/Zs/7GYA4=
=8F04
-----END PGP SIGNATURE-----

--===============4330607767444409616==--
]