[Pkg-openssl-devel] openssl_3.5.4-1_source.changes ACCEPTED into unstable

Debian FTP Masters ftpmaster at ftp-master.debian.org
Tue Sep 30 22:37:38 BST 2025


Thank you for your contribution to Debian.



Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 30 Sep 2025 21:54:39 +0200
Source: openssl
Architecture: source
Version: 3.5.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel at alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian at breakpoint.cc>
Changes:
 openssl (3.5.4-1) unstable; urgency=medium
 .
   * Import 3.5.4
    - CVE-2025-9230 (Out-of-bounds read & write in RFC 3211 KEK Unwrap)
    - CVE-2025-9231 (Timing side-channel in SM2 algorithm on 64 bit ARM)
    - CVE-2025-9232 (Out-of-bounds read in HTTP client no_proxy handling)
Checksums-Sha1:
 8d49e5279331734755a51db4c682488208ddbcba 2637 openssl_3.5.4-1.dsc
 b75daac8e10f189abe28a076ba5905d363e4801f 53190367 openssl_3.5.4.orig.tar.gz
 5f2dc895c3124ec1a04e17f2aa679f86ec49227c 833 openssl_3.5.4.orig.tar.gz.asc
 c6f80ed490365f89a566d622160e04898545fb2f 48888 openssl_3.5.4-1.debian.tar.xz
Checksums-Sha256:
 35e7e427f8ba3660b77ef5408433b748f7e9070eade4ba0e9452b13bd078ca23 2637 openssl_3.5.4-1.dsc
 967311f84955316969bdb1d8d4b983718ef42338639c621ec4c34fddef355e99 53190367 openssl_3.5.4.orig.tar.gz
 cfcabcfc6e43237392e0ab42e2326fceb71037036c2adaa7ecc7e251778e38f4 833 openssl_3.5.4.orig.tar.gz.asc
 17fc0e9b7df7bb5a5d33755c1efdc18b74a93affc47f5d9b62c4c8b17337be81 48888 openssl_3.5.4-1.debian.tar.xz
Files:
 f2f4a05ac6d4cc3b33e6fb618f286bcb 2637 utils optional openssl_3.5.4-1.dsc
 570a7ab371147b6ba72c6d0fed93131f 53190367 utils optional openssl_3.5.4.orig.tar.gz
 fc505832a9796504dcd48c14fd34c4cb 833 utils optional openssl_3.5.4.orig.tar.gz.asc
 9e18a9bb6671858377d99806acf12565 48888 utils optional openssl_3.5.4-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmjcRUYACgkQBWQfF1cS
+ltFjQwAkzDj742fQXyyLN2ETm8R2ZlT1orh1MIaJabLsadjmpdxr1MPqp3Dlnx7
FPXWqy3USmw2mST65KtR3CG7wvPYrjAPbL1q+Dz/MzOBZg2/qgjGidTy3wPJ1bhT
6leAo6WFCKyQ24HKTCCVO5c3cqerlvE8dS9OvPFpHL6rjUq/ilU/ulExBZJclFdx
Ki4FcD/g5gpeJt0ZmHlj5Ts+n6s3/AqS2GOxDEBUzT9MMhbTn9oteARMrV+6YykE
cv+WrS/c/gnFAVuEpd9JU93GcogbQ+7AnHG0NAF0F/KSdA5SE6edSWT595t4ie1A
0LoBKsKYhV5fMGG3z8R4rKmpsnCSWcGqDnh+wvhE+vmu23WUlpbVTt3RetrLVuhQ
ltnYa+oU06g4k70thKP8vLfR2WhYXRt2I87NY0vWBMJ0lFUMJkOfKQkqk1HrYalM
zfWBNeo9y3yi7sMAu5njUn2I3VIsbuMQwnmK+5fGcsdu7gWKGHiPI7AxvyfoUTGD
kwvtMQU7
=WTPp
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-openssl-devel/attachments/20250930/3c3b82c4/attachment.sig>


More information about the Pkg-openssl-devel mailing list