-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 03 Apr 2026 14:29:32 +0200 Source: openssl Binary: libcrypto3-udeb libssl-dev libssl3 libssl3-dbgsym libssl3-udeb openssl openssl-dbgsym Architecture: armel Version: 3.0.19-1~deb12u2 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Sebastian Andrzej Siewior Description: libcrypto3-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl3 - Secure Sockets Layer toolkit - shared libraries libssl3-udeb - ssl shared library - udeb (udeb) openssl - Secure Sockets Layer toolkit - cryptographic utility Changes: openssl (3.0.19-1~deb12u2) bookworm-security; urgency=medium . * CVE-2026-28387 ("Potential use-after-free in DANE client code") * CVE-2026-28389 ("Possible NULL dereference when processing CMS KeyAgreeRecipientInfo") * CVE-2026-28390 ("Possible NULL dereference when processing CMS KeyTransportRecipient Info") * CVE-2026-31789 ("Heap buffer overflow in hexadecimal conversion") * CVE-2026-31790 ("Incorrect failure handling in RSA KEM RSASVE encapsulation") Checksums-Sha1: 7a3b3575d4a690112d850f213ead38c982255139 1178968 libcrypto3-udeb_3.0.19-1~deb12u2_armel.udeb 42bfecf852dc6bf427c83b31d157e046ffdacc26 2115208 libssl-dev_3.0.19-1~deb12u2_armel.deb ffc0c822d5c723f954b1856897d0f880d4d80e11 4379744 libssl3-dbgsym_3.0.19-1~deb12u2_armel.deb d06f9fba03d6383cf085d5a36fd61162f5e6b91a 186112 libssl3-udeb_3.0.19-1~deb12u2_armel.udeb 733f66d414e40f0332e82101eecf6acd6b16b2f4 1641028 libssl3_3.0.19-1~deb12u2_armel.deb 0b4fc68d80af28c8ae74ecb04b98050f1053fcf0 648648 openssl-dbgsym_3.0.19-1~deb12u2_armel.deb 0eed2a888f4003973837446b9f056c55f546c8e4 7659 openssl_3.0.19-1~deb12u2_armel-buildd.buildinfo 130f7a2d567401c2a0074b41c751308959bebb7b 1394524 openssl_3.0.19-1~deb12u2_armel.deb Checksums-Sha256: 532e85d5909bcc0173ac7e78a6b4eba4507e9e30c163074c46fa51a2963d5361 1178968 libcrypto3-udeb_3.0.19-1~deb12u2_armel.udeb 0699b80dda4295563953437f50bf8ab9614f3f3c6c4b58b1bbcc1e437716884d 2115208 libssl-dev_3.0.19-1~deb12u2_armel.deb 2930ee5a0b05836ee98c9218215480ed52efe11bb0c7e9d9ff87afc0f80ddf7c 4379744 libssl3-dbgsym_3.0.19-1~deb12u2_armel.deb 4735c732dd30b0ece8d258d2ab260092c43b5be7f1f35c2268dacf8d87003350 186112 libssl3-udeb_3.0.19-1~deb12u2_armel.udeb 0a8391d809178322c0897ceffb654bf83b1b09e2790fa9b72b6ce93f17dd3a0f 1641028 libssl3_3.0.19-1~deb12u2_armel.deb 89711a5ce595280abfd6a1d85e693212d81e819cb84f76d768efca811a50b510 648648 openssl-dbgsym_3.0.19-1~deb12u2_armel.deb 6cd0d94f59a993b610d69e2aeb8d813bd9cb43d3ccc8a8e32822aade479d3eb8 7659 openssl_3.0.19-1~deb12u2_armel-buildd.buildinfo 168473b10574427d9eb32af4c91610ddc018bcc6c643af70bfc24772ac0cedf3 1394524 openssl_3.0.19-1~deb12u2_armel.deb Files: b63ce5d4e4f59cb88cba140bbdd335d9 1178968 debian-installer optional libcrypto3-udeb_3.0.19-1~deb12u2_armel.udeb a1beaccc1a9494ac0a8fe7d4d0682fc9 2115208 libdevel optional libssl-dev_3.0.19-1~deb12u2_armel.deb c21459aef8f45d24b84303880814f655 4379744 debug optional libssl3-dbgsym_3.0.19-1~deb12u2_armel.deb dffe9715da36b8b79493d0449b2f15e1 186112 debian-installer optional libssl3-udeb_3.0.19-1~deb12u2_armel.udeb 7dbad4a6b4c31b368dd530258af0333a 1641028 libs optional libssl3_3.0.19-1~deb12u2_armel.deb 94ea9fd68a21411abb739b264084eaec 648648 debug optional openssl-dbgsym_3.0.19-1~deb12u2_armel.deb 6fa3f4b763d9c377b05fe4a235511404 7659 utils optional openssl_3.0.19-1~deb12u2_armel-buildd.buildinfo 695ef9881f6e4cc596223efb996b9289 1394524 utils optional openssl_3.0.19-1~deb12u2_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmnP5cYACgkQOQKMdMnE H5MjWxAAplz+Lb2B8xFcrzptAbTjEfA435Ve2LL5ojQCSHcintmgb+IvAmSxtlEk JrJA13YvSMDr2zOndVBE0uHKcvisVi+F7YC8HzNZsxLoSwbTtC1HNhjJwR4EJQbm oOvm/T3vSDW+8xfhoYvgeqbx2GgBahWTnmfCeQPjZ2vMy5yh3gU9tm3n8nGJqx/Y pijCAaymnv+AotaitzmCVeRYNRocVYFPa1li6VCz3s9y0EdPh+V8TdAZxGHGaKuG Uafn29fyBVOMsHKQajiOVG9DMUELqeHOUEHfRF8WnX+lLkXoSYFwiMmg3mGWtocr W1duUGdrGNMSzjG8TmSnOcw0I1uHEFcqC+FkFygJeCaob7ayKz7kc61KThywGpUE 1+g0F0lhjBYFsmgF+XzgSdUsoadTnIsk01IWHmAYUai4huEe8ENI6jK7tnwOTOBe I3vQQb6aghns5symT000heC3l4pPcqqjGmLu3qk36oHLDJTRsSaYMMTl5vKtE9SV bR/9tUAeRqWhQxUvJrLBEm1emIGgdkDREUrb3xECy+i0uwUEF6kWqed242/GY/k6 pZ91TeeYjSDByyPlDH+dBDKWE7LdYAeojYeMfBe3t1TRCTSp0Tc736zti9U0nydt 3Phpv+SnimCKYt9ix/6ST3yD+dTOSt7/nLXRp4azQgYU5fqGM9A= =EUYp -----END PGP SIGNATURE-----