[Pkg-openssl-devel] openssl_3.5.7-1~deb13u3_source.changes ACCEPTED into proposed-updates
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Fri Oct 2 16:22:40 BST 2026
Thank you for your contribution to Debian.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 29 Sep 2026 22:10:28 +0200
Source: openssl
Architecture: source
Version: 3.5.7-1~deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel at alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian at breakpoint.cc>
Changes:
openssl (3.5.7-1~deb13u3) trixie-security; urgency=medium
.
* CVE-2026-84782 ("DTLS Retransmits Handshake Messages From a Stale Buffer
Offset")
* CVE-2026-35189 ("Memory Allocation in Relative CRLDP Processing")
* CVE-2026-35191 ("QUIC Unvalidated Amplification Credit may be Over
Accounted")
* CVE-2026-54872 ("Timing Side-Channel in Scalar Multiplication for Non-NIST
EC Curves")
* CVE-2026-54875 ("Non-Constant-Time SM2 Scalar Multiplication on ARM64 and
RISC-V")
* CVE-2026-72897 ("Out-of-Bounds Access After SSL_set_SSL_CTX() During a
Handshake")
* CVE-2026-75804 ("QUIC Connection-Level Flow Control is Not Enforced for
Streams")
* CVE-2026-75805 ("NULL Pointer Dereference in CMP Client Revocation
Response Handling")
* CVE-2026-75806 ("Unauthenticated and Undersized DTLS 1.2 AEAD Record
Causes DoS")
* CVE-2026-77696 ("Timing Side-Channel in SM2 Signature Generation")
* CVE-2026-84784 ("QUIC: Unbounded RETIRE_CONNECTION_ID Backlog")
* CVE-2026-42772 and CVE-2026-54873 ("improved QUIC
stream reassembly implementation")
Checksums-Sha1:
db56cd5070f847d98b8fec3dde05ce8ee276ba64 2710 openssl_3.5.7-1~deb13u3.dsc
53d331880fbde8e6fe25870d5325a61201f6264d 53153930 openssl_3.5.7.orig.tar.gz
9408998095f984b36591732286ef1df1ba7ce492 833 openssl_3.5.7.orig.tar.gz.asc
11a6b388b1ce45f8c60021ed66f8772f7c963c62 147344 openssl_3.5.7-1~deb13u3.debian.tar.xz
Checksums-Sha256:
9cdb0d9daf0773ca5c0f3f5ea1fc59b1106a99e005a5c048948b826e8d3b47e1 2710 openssl_3.5.7-1~deb13u3.dsc
a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8 53153930 openssl_3.5.7.orig.tar.gz
d3d082bee3f658c31db53af625eceecf29d777c7010394bed5787ebcc98abdf2 833 openssl_3.5.7.orig.tar.gz.asc
0a427fdc3e773f4119a7dd5b36d1f0903a163cf4ea15d812bb823b251ff1cbc5 147344 openssl_3.5.7-1~deb13u3.debian.tar.xz
Files:
550d94e5b92604e13ea34275bbdd8007 2710 utils optional openssl_3.5.7-1~deb13u3.dsc
36608cd5445f708d0c2200aea9682c35 53153930 utils optional openssl_3.5.7.orig.tar.gz
1550a37dc3382ec617b5fd7d4140b92c 833 utils optional openssl_3.5.7.orig.tar.gz.asc
6f660602c694d6fc1439abf05cb3d29e 147344 utils optional openssl_3.5.7-1~deb13u3.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmq8HwkACgkQBWQfF1cS
+lsyRAv/W28RHyytNa+2VkFpyNe5tn6GCXh1ShU1oJ8te7YW/dqPAhJQBWXpT/vQ
UuwBSpkhdGHVXX3gpoIQXnH3JaH9RufrtiRfz8VejZmZNAbsSDem6b0HSWLLYPto
l+7+hh8LOeXKKpjl32a2gf+T0iuTbmlibR7QQHKDlqbZlNdsO7xu9XuDjQ4H9ZBc
wpo0YoS5SJdofQLN+IHKFeZmR8/GUUdTiaPnVLVLuXr/7qh449y7H6UoP+EJwCkS
kgdOCALJFMXqdcpXifS4/VnRTZjUYPBbzxckNT3fP76m1OmHY7ma+HeOIoYSTc0z
rfAet5p49q7NnyKt40bDy0vYYh4GgIxTrxT3pY+UeBCDlAc5rBc49GkKeDcCNPHb
KoBFXAIsCnOc61ZDK3Gmh+Kcft5HovbsPgctlZCx87LTPLBC3InHY819HSxrqn8p
QWPiPbpQSwssrafp8DufraIfv1bx0G74Yfj/Tfc2S+CKVeHPISnJjkryqUowDi0g
BWCpuY1V
=6VEk
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-openssl-devel/attachments/20261002/fbcc61b0/attachment.sig>
More information about the Pkg-openssl-devel
mailing list