[Pkg-openssl-devel] openssl_3.5.7-1~deb13u3_source.changes ACCEPTED into proposed-updates->stable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Wed Sep 30 07:20:36 BST 2026


Thank you for your contribution to Debian.

Mapping stable-security to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 29 Sep 2026 22:10:28 +0200
Source: openssl
Architecture: source
Version: 3.5.7-1~deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenSSL Team <pkg-openssl-devel at alioth-lists.debian.net>
Changed-By: Sebastian Andrzej Siewior <sebastian at breakpoint.cc>
Changes:
 openssl (3.5.7-1~deb13u3) trixie-security; urgency=medium
 .
   * CVE-2026-84782 ("DTLS Retransmits Handshake Messages From a Stale Buffer
     Offset")
   * CVE-2026-35189 ("Memory Allocation in Relative CRLDP Processing")
   * CVE-2026-35191 ("QUIC Unvalidated Amplification Credit may be Over
     Accounted")
   * CVE-2026-54872 ("Timing Side-Channel in Scalar Multiplication for Non-NIST
     EC Curves")
   * CVE-2026-54875 ("Non-Constant-Time SM2 Scalar Multiplication on ARM64 and
     RISC-V")
   * CVE-2026-72897 ("Out-of-Bounds Access After SSL_set_SSL_CTX() During a
     Handshake")
   * CVE-2026-75804 ("QUIC Connection-Level Flow Control is Not Enforced for
     Streams")
   * CVE-2026-75805 ("NULL Pointer Dereference in CMP Client Revocation
     Response Handling")
   * CVE-2026-75806 ("Unauthenticated and Undersized DTLS 1.2 AEAD Record
     Causes DoS")
   * CVE-2026-77696 ("Timing Side-Channel in SM2 Signature Generation")
   * CVE-2026-84784 ("QUIC: Unbounded RETIRE_CONNECTION_ID Backlog")
   * CVE-2026-42772 and CVE-2026-54873 ("improved QUIC
     stream reassembly implementation")
Checksums-Sha1:
 db56cd5070f847d98b8fec3dde05ce8ee276ba64 2710 openssl_3.5.7-1~deb13u3.dsc
 53d331880fbde8e6fe25870d5325a61201f6264d 53153930 openssl_3.5.7.orig.tar.gz
 9408998095f984b36591732286ef1df1ba7ce492 833 openssl_3.5.7.orig.tar.gz.asc
 11a6b388b1ce45f8c60021ed66f8772f7c963c62 147344 openssl_3.5.7-1~deb13u3.debian.tar.xz
Checksums-Sha256:
 9cdb0d9daf0773ca5c0f3f5ea1fc59b1106a99e005a5c048948b826e8d3b47e1 2710 openssl_3.5.7-1~deb13u3.dsc
 a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8 53153930 openssl_3.5.7.orig.tar.gz
 d3d082bee3f658c31db53af625eceecf29d777c7010394bed5787ebcc98abdf2 833 openssl_3.5.7.orig.tar.gz.asc
 0a427fdc3e773f4119a7dd5b36d1f0903a163cf4ea15d812bb823b251ff1cbc5 147344 openssl_3.5.7-1~deb13u3.debian.tar.xz
Files:
 550d94e5b92604e13ea34275bbdd8007 2710 utils optional openssl_3.5.7-1~deb13u3.dsc
 36608cd5445f708d0c2200aea9682c35 53153930 utils optional openssl_3.5.7.orig.tar.gz
 1550a37dc3382ec617b5fd7d4140b92c 833 utils optional openssl_3.5.7.orig.tar.gz.asc
 6f660602c694d6fc1439abf05cb3d29e 147344 utils optional openssl_3.5.7-1~deb13u3.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmq8HwkACgkQBWQfF1cS
+lsyRAv/W28RHyytNa+2VkFpyNe5tn6GCXh1ShU1oJ8te7YW/dqPAhJQBWXpT/vQ
UuwBSpkhdGHVXX3gpoIQXnH3JaH9RufrtiRfz8VejZmZNAbsSDem6b0HSWLLYPto
l+7+hh8LOeXKKpjl32a2gf+T0iuTbmlibR7QQHKDlqbZlNdsO7xu9XuDjQ4H9ZBc
wpo0YoS5SJdofQLN+IHKFeZmR8/GUUdTiaPnVLVLuXr/7qh449y7H6UoP+EJwCkS
kgdOCALJFMXqdcpXifS4/VnRTZjUYPBbzxckNT3fP76m1OmHY7ma+HeOIoYSTc0z
rfAet5p49q7NnyKt40bDy0vYYh4GgIxTrxT3pY+UeBCDlAc5rBc49GkKeDcCNPHb
KoBFXAIsCnOc61ZDK3Gmh+Kcft5HovbsPgctlZCx87LTPLBC3InHY819HSxrqn8p
QWPiPbpQSwssrafp8DufraIfv1bx0G74Yfj/Tfc2S+CKVeHPISnJjkryqUowDi0g
BWCpuY1V
=6VEk
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-openssl-devel/attachments/20260930/ec9726f2/attachment.sig>


More information about the Pkg-openssl-devel mailing list