Bug#1130152: libgnutls30t64: extensions shuffling regression in 3.8.5 causes handshake failure with certain servers

Simon McVittie smcv at collabora.com
Mon Mar 9 17:28:29 GMT 2026


Control: tags -1 + patch

On Mon, 09 Mar 2026 at 12:42:35 +0000, Simon McVittie wrote:
> This appears to have been fixed by
> https://gitlab.com/gnutls/gnutls/-/merge_requests/1930
> after the 3.8.9 release, commit
> <https://gitlab.com/gnutls/gnutls/-/commit/dc5ee80c3a28577e9de0f82fb08164e4c02b96af>,
> but unfortunately that commit didn't make it into Debian 13. Please
> could this change be backported? (I haven't yet verified that this change
> resolves the issue, I'll look into that next.)

Yes, that seems to work as expected. Please see
https://salsa.debian.org/gnutls-team/gnutls/-/merge_requests/5 or the
attached.

    smcv
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 51_handshake-only-shuffle-extensions-in-the-first-Client-Hel.patch
Type: text/x-diff
Size: 7133 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gnutls-maint/attachments/20260309/35771d1b/attachment-0001.patch>


More information about the Pkg-gnutls-maint mailing list