Bug#956649: libgnutls30: Visiting some websites results in an "Unexpected TLS packet during handshake" error

Matthew Horan matt at matthoran.com
Mon Apr 13 22:25:54 BST 2020


Package: libgnutls30
Version: 3.6.7-4+deb10u3mhoran0
Severity: normal

Dear Maintainer,

This error is documented best in an upstream issue:
https://gitlab.com/gnutls/gnutls/-/issues/841.

In my experience this issue manifests in the liferea feed reader, and
can be quite persistent.

The issue is resolved in newer releases by the patch in
https://gitlab.com/gnutls/gnutls/-/merge_requests/1087. I applied this
patch to the version of libgnutls30 in buster and it resolves the issue
for me.

I'm hoping that either the patch above can be included in Debian buster,
or a later release can be backported (3.6.13 from bullseye would be
sufficient.)

Thanks,
Matt

-- System Information:
Debian Release: 10.3
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-8-amd64 (SMP w/8 CPU cores)
Kernel taint flags: TAINT_WARN, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libgnutls30 depends on:
ii  libc6          2.28-10
ii  libgmp10       2:6.1.2+dfsg-4
ii  libhogweed4    3.4.1-1
ii  libidn2-0      2.0.5-1+deb10u1
ii  libnettle6     3.4.1-1
ii  libp11-kit0    0.23.15-2
ii  libtasn1-6     4.13-3
ii  libunistring2  0.9.10-1

libgnutls30 recommends no packages.

Versions of packages libgnutls30 suggests:
pn  gnutls-bin  <none>

-- no debconf information



More information about the Pkg-gnutls-maint mailing list