[Pkg-openssl-devel] openssl_4.0.2-1_source.changes ACCEPTED into experimental

Debian FTP Masters ftpmaster at ftp-master.debian.org
Tue Aug 25 21:29:22 BST 2026


Thank you for your contribution to Debian.



Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 25 Aug 2026 21:19:42 +0200
Source: openssl
Architecture: source
Version: 4.0.2-1
Distribution: experimental
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel at alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian at breakpoint.cc>
Closes: 1143841 1144615 1145172
Changes:
 openssl (4.0.2-1) experimental; urgency=medium
 .
   * Import 4.0.2
     - CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
       INITIAL Packet")
     - CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
     - CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
       protectionAlg")
     - CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
       a Missing Certificate")
     - CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
       Epoch")
     - CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
       Validation")
     - CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
     - CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
       Exhaustion")
     - CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
       EVP_Cipher()") (Closes: #1145172)
     - CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
       Queue") (Closes: #1144615)
     - CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking") (Closes: #1143841)
Checksums-Sha1:
 794c0bb4dd48c785968e761727e0a8468c8d77c5 2669 openssl_4.0.2-1.dsc
 236d35817b0adda5c07572ae24bcbe643b05c71d 55153883 openssl_4.0.2.orig.tar.gz
 084520b62aad0cbc3590b8384e00fd9f79c98c7f 931 openssl_4.0.2.orig.tar.gz.asc
 1f02deb39262b89837649dac0db9720eec231fdb 51124 openssl_4.0.2-1.debian.tar.xz
Checksums-Sha256:
 8e9ad392230018f1172b8a3ba299ea389d8b5ddafc6128ed8d8321d04eee0dda 2669 openssl_4.0.2-1.dsc
 736b467530f916737b7031310ccb21d8218c6229e61e8e160cd1d3458cd543a8 55153883 openssl_4.0.2.orig.tar.gz
 2eade0aa5a3734301b6e53dc25b5c681a4aec7a2d3b2632c74bbac9b65cb9e60 931 openssl_4.0.2.orig.tar.gz.asc
 3a7cdef57c3a8dd884d460ab50fbe5eb7c6a825106312e5ea966ce4cca4d9941 51124 openssl_4.0.2-1.debian.tar.xz
Files:
 a8a93931fe4324de5fe358ec5c824888 2669 utils optional openssl_4.0.2-1.dsc
 9d256ddfa581e1982c005ab03890754d 55153883 utils optional openssl_4.0.2.orig.tar.gz
 893cd5f159d68140ab9011c07adfae84 931 utils optional openssl_4.0.2.orig.tar.gz.asc
 c00ee3a33f8ae40a85c2c5d076fec94e 51124 utils optional openssl_4.0.2-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqN9pkACgkQBWQfF1cS
+lsQNAv/VkrkQHQSnatAnghMENkaLnk7pYnpTn5DjaRhrdcD+quGFDVx0pyO0leY
C9FX2yDx42OzAHVOQRWsuP6mP/CtvfNTXuLJaZFKwolQ2nXx23ZDic8/evf0CFIn
9Ddwu+vN6DIvK9fH40ivWyCIo6eig2xVAFdgM9zIkrNOr6iLMn88IeRASQyPvD+v
ryFIC18La+rPBIxmrVilVpZPI/P8j4g5bQN6g4cRXgXP4HWrAxot2OjsHdmrYEoZ
05aicp8eoMyL1MpfZKUqiZacL7JiM63e/6z8V4lNeaeLx24o6nztM+bQtfeGpCmS
jnVW+Q0oY4p0vbQ5FuZgWZYRDQ+GMVMz1K7Y3J7SbhqiHNFog06c2TqYua1dY8PA
S+cSDvCtwmyMytHodWs0KHOdjITaNtlgnvp/nlWR8Ut8BaLmOnMVo6FJp50PP+CW
i7nvFU6JOPkVaa39WirI3v+ZCJjoKDddcOowS56BA4eDP6nKw71d/BqcoxV2hwMs
EGZXnE+f
=WxoT
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-openssl-devel/attachments/20260825/91facb1c/attachment.sig>


More information about the Pkg-openssl-devel mailing list