[Pkg-openssl-devel] openssl_3.6.4-1_source.changes ACCEPTED into unstable
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Tue Aug 25 21:29:11 BST 2026
Thank you for your contribution to Debian.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 25 Aug 2026 20:40:24 +0200
Source: openssl
Architecture: source
Version: 3.6.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel at alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian at breakpoint.cc>
Closes: 1143841 1144615 1145172
Changes:
openssl (3.6.4-1) unstable; urgency=medium
.
* Import 3.6.4
- CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
INITIAL Packet")
- CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
- CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
protectionAlg")
- CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
a Missing Certificate")
- CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
Epoch")
- CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
Validation")
- CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
- CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
Exhaustion")
- CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
EVP_Cipher()") (Closes: #1145172)
- CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
Queue") (Closes: #1144615)
- CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking") (Closes: #1143841)
Checksums-Sha1:
d2744582a6895e5259ff20eef8d9cb657b9c1ad2 2675 openssl_3.6.4-1.dsc
85aed0a4acf51f2e0d448310fd61099acf4d100a 55003802 openssl_3.6.4.orig.tar.gz
987e36db37d0fcb54cd8a34fffa0259c90fb5cef 931 openssl_3.6.4.orig.tar.gz.asc
e667314305cb4504a1ab9f9c7c7b28e16ded1e6b 51852 openssl_3.6.4-1.debian.tar.xz
Checksums-Sha256:
c300906132d616fcce9b704f026fe2b15a83407c1b955914f0f8fe1dbb98b1af 2675 openssl_3.6.4-1.dsc
9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef 55003802 openssl_3.6.4.orig.tar.gz
2f957d2a61971714d256a6ed58a1336a687ee19859538514763f880aa89877de 931 openssl_3.6.4.orig.tar.gz.asc
79b60079960546d53abe36a93b52c93a965af8ea8c814d59f3865bbb5ebc1371 51852 openssl_3.6.4-1.debian.tar.xz
Files:
3fe339af785ae55358a60ea19dd6dd62 2675 utils optional openssl_3.6.4-1.dsc
f771f53e0ce36d806d64e15f4d3a36d3 55003802 utils optional openssl_3.6.4.orig.tar.gz
92607567a7850af08af082a3ff639bd4 931 utils optional openssl_3.6.4.orig.tar.gz.asc
fbf687970996cb670773a19166a0c392 51852 utils optional openssl_3.6.4-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqN9pwACgkQBWQfF1cS
+luPHgv/TBeXuNXafQCkFy7ncYHsPRS/lXgVjWU0Fzto1xzAJ3LGC7iMuWDex4Y+
5TeW78JTidVw1Yh3g2i/290IJwFgNHPI6gX+l01IFVhRbEX0rhFBCsIZDGLZ9qbf
sqwRxSKTMZYj9oXXV8DKtrx8eExNeixUuEzvQBHwukZ4Ta90uPtPi4okcAYAYDkz
+to8+gUc6KJNW1BCFUDpC7AOPDHFNznEx1+NhjsO2Hm9r5LX8ag6r8s8fbtjr6Mb
KPCltrLE8yvHcYRjjL7zLSW5s947dryHDVFyQbZlkfrawXme6bcBIji2jxnyrn2C
r0JNLHknfuZQe3Yrbsn9uJoQsuhR7ObgpE8SUPct36RlBfWEgGFkP57SqZxGx5xn
GyChfVLwMgvwYUn11pfdP5xdthqQDhPG18pLmDnr0f7AuLrPVcInn3QLBYCd1BbN
4P3RJItAH9XPNBehpXd61Sa/ts3BfnqZjFk+piThUbJn3cm46rk3dN2RxpP/ve+p
sX5yqSog
=pgn/
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-openssl-devel/attachments/20260825/2aff6bce/attachment.sig>
More information about the Pkg-openssl-devel
mailing list