[From nobody Fri Aug 28 23:13:08 2026
Received: (at submit) by bugs.debian.org; 26 Mar 2026 07:34:06 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-18.9 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,FOURLA,HAS_PACKAGE,NO_RELAYS,XMAILER_REPORTBUG
 autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 33; hammy, 150; neutral, 132; spammy,
 0. spammytokens: hammytokens:0.000-+--XDebbugsCc,
 0.000-+--X-Debbugs-Cc, 0.000-+--forky, 0.000-+--HTo:N*Debian,
 0.000-+--H*Ad:N*Bug
Return-path: &lt;pkk@spth.de&gt;
Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;pkk@spth.de&gt;) id 1w5fED-003soS-1X
 for submit@bugs.debian.org; Thu, 26 Mar 2026 07:34:06 +0000
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Philipp Klaus Krause &lt;pkk@spth.de&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: libssl3t64: &quot;LS alert,
 bad record mac (532)&quot; / &quot;decryption failed or bad record mac&quot; since
 3.6.1 on ppc64
Message-ID: &lt;177451043783.830883.3277498204805414604.reportbug@nemesis&gt;
X-Mailer: reportbug 13.2.0
Date: Thu, 26 Mar 2026 08:33:57 +0100
Delivered-To: submit@bugs.debian.org

Package: libssl3t64
Version: 3.6.0-2
Severity: normal
X-Debbugs-Cc: debian-powerpc@lists.debian.org, pkk@spth.de
User: debian-powerpc@lists.debian.org
Usertags: ppc64

Dear Maintainer,

about a week ago, I upgraded libssl3t64 on my ppc64 system to 3.6.1-3. This resulted in failures (see below). After downgrading to 3.6.0-2, the failures disappeared. An amd64 system on the same network was not affected (there 3.6.1 works).

Failure example:

philipp@nemesis:/tmp$ curl --verbose https://www.google.com
* Host www.google.com:443 was resolved.
* IPv6: 2001:4860:482d:7700::, 2001:4860:4829:7700::, 2001:4860:4827:7700::, 2001:4860:482c:7700::, 2001:4860:4828:7700::, 2001:4860:482a:7700::, 2001:4860:482b:7700::, 2001:4860:4826:7700::
* IPv4: 142.251.156.119, 142.251.154.119, 142.251.152.119, 142.251.150.119, 142.251.155.119, 142.251.153.119, 142.251.157.119, 142.251.151.119
*   Trying [2001:4860:482d:7700::]:443...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* SSL Trust Anchors:
*   CAfile: /etc/ssl/certs/ca-certificates.crt
*   CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS alert, bad record mac (532):
* TLS connect error: error:0A000119:SSL routines::decryption failed or bad record mac
* closing connection #0
curl: (35) TLS connect error: error:0A000119:SSL routines::decryption failed or bad record mac


-- System Information:
Debian Release: forky/sid
  APT prefers unreleased
  APT policy: (500, 'unreleased'), (500, 'unstable')
Architecture: ppc64

Kernel: Linux 6.19.8+deb14-powerpc64-64k (SMP w/176 CPU threads; PREEMPT)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libssl3t64 depends on:
ii  libc6                    2.42-13
ii  libzstd1                 1.5.7+dfsg-3+b1
ii  openssl-provider-legacy  3.6.1-3
ii  zlib1g                   1:1.3.dfsg+really1.3.1-3

libssl3t64 recommends no packages.

libssl3t64 suggests no packages.

-- no debconf information
]