[From nobody Tue Aug 25 21:31:09 2026
Received: (at 1145172-close) by bugs.debian.org; 25 Aug 2026 20:29:24 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
 FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,
 SPF_HELO_PASS,SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 4; hammy, 150; neutral, 379; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--HX-DAK:process-upload,
 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo.
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from mailly.debian.org ([2001:41b8:202:deb:6564:a62:52c3:4b72]:51132)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wyxls-005XOk-2s for 1145172-close@bugs.debian.org;
 Tue, 25 Aug 2026 20:29:24 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by mailly.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wyxlr-0024cs-28 for 1145172-close@bugs.debian.org;
 Tue, 25 Aug 2026 20:29:23 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=p0+RFzHv/IAs37PL3Oz2+jpbqLLi6jUFklF7aLUtVxg=; b=Yw88Uq1yDbIPO3CifupPDKkxj+
 nXyHP0UJXDxbFWEViegyDdQp7v8GZYHHYbxHKlafl0016vNhy1uSbZePuCHp5ZSHjzKy4VDrl73+t
 Rp5QjUIL6zOyI568uJRqPqtVX/hOGGAGhp8cHSvosvLTadoxNRd1jkGfmpJKoDq5CSM8lCtF5gjZB
 kb5zC+V14i7VgKdWBf+9BbZ3VBxRIHxiNAerMOuTh8sxeDT60Sd8iRQdyh789QMi/I1+dlCxELmQN
 c71WhxF7m1E///9dHvZv9/FDS7WmH2TUfRj7QEF0myppytXUF/HCB0366hbCpWTw760y+lnmlZ6Gr
 4Rrh8dfw==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wyxlq-0000000FYdf-37rI; Tue, 25 Aug 2026 20:29:22 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Sebastian Andrzej Siewior &lt;sebastian@breakpoint.cc&gt;
To: 1145172-close@bugs.debian.org
X-DAK: dak process-upload
X-Debian: DAK
X-Debian-Package: openssl
Debian: DAK
Debian-Changes: openssl_4.0.2-1_source.changes
Debian-Source: openssl
Debian-Version: 4.0.2-1
Debian-Architecture: source
Debian-Suite: experimental
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1145172: fixed in openssl 4.0.2-1
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============0054811643821033021==&quot;
Message-Id: &lt;E1wyxlq-0000000FYdf-37rI@fasolo.debian.org&gt;
Date: Tue, 25 Aug 2026 20:29:22 +0000
X-CrossAssassin-Score: 6

--===============0054811643821033021==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: openssl
Source-Version: 4.0.2-1
Done: Sebastian Andrzej Siewior &lt;sebastian@breakpoint.cc&gt;

We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145172@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior &lt;sebastian@breakpoint.cc&gt; (supplier of updated open=
ssl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 25 Aug 2026 21:19:42 +0200
Source: openssl
Architecture: source
Version: 4.0.2-1
Distribution: experimental
Urgency: medium
Maintainer: Debian OpenSSL Team &lt;pkg-openssl-devel@alioth-lists.debian.net&gt;
Changed-By: Sebastian Andrzej Siewior &lt;sebastian@breakpoint.cc&gt;
Closes: 1143841 1144615 1145172
Changes:
 openssl (4.0.2-1) experimental; urgency=3Dmedium
 .
   * Import 4.0.2
     - CVE-2026-18798 (&quot;QUIC Server May Trigger Double Free When Processing
       INITIAL Packet&quot;)
     - CVE-2026-63072 (&quot;Heap Buffer Overflow in CMS Key Unwrapping&quot;)
     - CVE-2026-63076 (&quot;Invalid Pointer Dereference in CMP Server via Crafted
       protectionAlg&quot;)
     - CVE-2026-14457 (&quot;RPK Server Signature Algorithm Selection Can Derefere=
nce
       a Missing Certificate&quot;)
     - CVE-2026-54874 (&quot;Excessive Memory Use Buffering DTLS Records for a Fut=
ure
       Epoch&quot;)
     - CVE-2026-63073 (&quot;Untrusted Sender DN Used as Format String in CMP Resp=
onse
       Validation&quot;)
     - CVE-2026-63074 (&quot;CMP Indefinite Cache Growth of ExtraCerts&quot;)
     - CVE-2026-63075 (&quot;QUIC ACK-only Packet Retention Can Cause Memory
       Exhaustion&quot;)
     - CVE-2026-75803 (&quot;AEAD Forgeries with Empty Ciphertext When Using
       EVP_Cipher()&quot;) (Closes: #1145172)
     - CVE-2026-14456 (&quot;Unbounded Memory Growth in QUIC Server Incoming Chann=
el
       Queue&quot;) (Closes: #1144615)
     - CVE-2026-54876 (&quot;Client-Side Memory Leak in OCSP Response Checking&quot;) (=
Closes: #1143841)
Checksums-Sha1:
 794c0bb4dd48c785968e761727e0a8468c8d77c5 2669 openssl_4.0.2-1.dsc
 236d35817b0adda5c07572ae24bcbe643b05c71d 55153883 openssl_4.0.2.orig.tar.gz
 084520b62aad0cbc3590b8384e00fd9f79c98c7f 931 openssl_4.0.2.orig.tar.gz.asc
 1f02deb39262b89837649dac0db9720eec231fdb 51124 openssl_4.0.2-1.debian.tar.xz
Checksums-Sha256:
 8e9ad392230018f1172b8a3ba299ea389d8b5ddafc6128ed8d8321d04eee0dda 2669 openss=
l_4.0.2-1.dsc
 736b467530f916737b7031310ccb21d8218c6229e61e8e160cd1d3458cd543a8 55153883 op=
enssl_4.0.2.orig.tar.gz
 2eade0aa5a3734301b6e53dc25b5c681a4aec7a2d3b2632c74bbac9b65cb9e60 931 openssl=
_4.0.2.orig.tar.gz.asc
 3a7cdef57c3a8dd884d460ab50fbe5eb7c6a825106312e5ea966ce4cca4d9941 51124 opens=
sl_4.0.2-1.debian.tar.xz
Files:
 a8a93931fe4324de5fe358ec5c824888 2669 utils optional openssl_4.0.2-1.dsc
 9d256ddfa581e1982c005ab03890754d 55153883 utils optional openssl_4.0.2.orig.=
tar.gz
 893cd5f159d68140ab9011c07adfae84 931 utils optional openssl_4.0.2.orig.tar.g=
z.asc
 c00ee3a33f8ae40a85c2c5d076fec94e 51124 utils optional openssl_4.0.2-1.debian=
.tar.xz

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqN9pkACgkQBWQfF1cS
+lsQNAv/VkrkQHQSnatAnghMENkaLnk7pYnpTn5DjaRhrdcD+quGFDVx0pyO0leY
C9FX2yDx42OzAHVOQRWsuP6mP/CtvfNTXuLJaZFKwolQ2nXx23ZDic8/evf0CFIn
9Ddwu+vN6DIvK9fH40ivWyCIo6eig2xVAFdgM9zIkrNOr6iLMn88IeRASQyPvD+v
ryFIC18La+rPBIxmrVilVpZPI/P8j4g5bQN6g4cRXgXP4HWrAxot2OjsHdmrYEoZ
05aicp8eoMyL1MpfZKUqiZacL7JiM63e/6z8V4lNeaeLx24o6nztM+bQtfeGpCmS
jnVW+Q0oY4p0vbQ5FuZgWZYRDQ+GMVMz1K7Y3J7SbhqiHNFog06c2TqYua1dY8PA
S+cSDvCtwmyMytHodWs0KHOdjITaNtlgnvp/nlWR8Ut8BaLmOnMVo6FJp50PP+CW
i7nvFU6JOPkVaa39WirI3v+ZCJjoKDddcOowS56BA4eDP6nKw71d/BqcoxV2hwMs
EGZXnE+f
=3DWxoT
-----END PGP SIGNATURE-----


--===============0054811643821033021==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCao37IgAKCRCb9qggYcy5
IX1IAP0UR+sxr/w4C8admcTkEt9Tvqc6bkcsu5utp3YgDl5x7wEA0AIt2C2qjyzb
8JBSxE47jN5l/QLHrLqz7gjdZwwQfg0=
=DrBf
-----END PGP SIGNATURE-----

--===============0054811643821033021==--
]