[Pkg-openssl-devel] openssl_3.6.4-1_source.changes ACCEPTED into unstable

Debian FTP Masters ftpmaster at ftp-master.debian.org
Tue Aug 25 21:29:11 BST 2026


Thank you for your contribution to Debian.



Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 25 Aug 2026 20:40:24 +0200
Source: openssl
Architecture: source
Version: 3.6.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel at alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian at breakpoint.cc>
Closes: 1143841 1144615 1145172
Changes:
 openssl (3.6.4-1) unstable; urgency=medium
 .
   * Import 3.6.4
     - CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
       INITIAL Packet")
     - CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
     - CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
       protectionAlg")
     - CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
       a Missing Certificate")
     - CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
       Epoch")
     - CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
       Validation")
     - CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
     - CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
       Exhaustion")
     - CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
       EVP_Cipher()") (Closes: #1145172)
     - CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
       Queue") (Closes: #1144615)
     - CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking") (Closes: #1143841)
Checksums-Sha1:
 d2744582a6895e5259ff20eef8d9cb657b9c1ad2 2675 openssl_3.6.4-1.dsc
 85aed0a4acf51f2e0d448310fd61099acf4d100a 55003802 openssl_3.6.4.orig.tar.gz
 987e36db37d0fcb54cd8a34fffa0259c90fb5cef 931 openssl_3.6.4.orig.tar.gz.asc
 e667314305cb4504a1ab9f9c7c7b28e16ded1e6b 51852 openssl_3.6.4-1.debian.tar.xz
Checksums-Sha256:
 c300906132d616fcce9b704f026fe2b15a83407c1b955914f0f8fe1dbb98b1af 2675 openssl_3.6.4-1.dsc
 9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef 55003802 openssl_3.6.4.orig.tar.gz
 2f957d2a61971714d256a6ed58a1336a687ee19859538514763f880aa89877de 931 openssl_3.6.4.orig.tar.gz.asc
 79b60079960546d53abe36a93b52c93a965af8ea8c814d59f3865bbb5ebc1371 51852 openssl_3.6.4-1.debian.tar.xz
Files:
 3fe339af785ae55358a60ea19dd6dd62 2675 utils optional openssl_3.6.4-1.dsc
 f771f53e0ce36d806d64e15f4d3a36d3 55003802 utils optional openssl_3.6.4.orig.tar.gz
 92607567a7850af08af082a3ff639bd4 931 utils optional openssl_3.6.4.orig.tar.gz.asc
 fbf687970996cb670773a19166a0c392 51852 utils optional openssl_3.6.4-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqN9pwACgkQBWQfF1cS
+luPHgv/TBeXuNXafQCkFy7ncYHsPRS/lXgVjWU0Fzto1xzAJ3LGC7iMuWDex4Y+
5TeW78JTidVw1Yh3g2i/290IJwFgNHPI6gX+l01IFVhRbEX0rhFBCsIZDGLZ9qbf
sqwRxSKTMZYj9oXXV8DKtrx8eExNeixUuEzvQBHwukZ4Ta90uPtPi4okcAYAYDkz
+to8+gUc6KJNW1BCFUDpC7AOPDHFNznEx1+NhjsO2Hm9r5LX8ag6r8s8fbtjr6Mb
KPCltrLE8yvHcYRjjL7zLSW5s947dryHDVFyQbZlkfrawXme6bcBIji2jxnyrn2C
r0JNLHknfuZQe3Yrbsn9uJoQsuhR7ObgpE8SUPct36RlBfWEgGFkP57SqZxGx5xn
GyChfVLwMgvwYUn11pfdP5xdthqQDhPG18pLmDnr0f7AuLrPVcInn3QLBYCd1BbN
4P3RJItAH9XPNBehpXd61Sa/ts3BfnqZjFk+piThUbJn3cm46rk3dN2RxpP/ve+p
sX5yqSog
=pgn/
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-openssl-devel/attachments/20260825/2aff6bce/attachment.sig>


More information about the Pkg-openssl-devel mailing list