-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 03 Apr 2026 12:05:32 +0200 Source: openssl Binary: libcrypto3-udeb libssl-dev libssl3-udeb libssl3t64 libssl3t64-dbgsym openssl openssl-dbgsym openssl-provider-fips openssl-provider-fips-dbgsym openssl-provider-legacy openssl-provider-legacy-dbgsym Architecture: armhf Version: 3.5.5-1~deb13u2 Distribution: trixie-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Sebastian Andrzej Siewior Description: libcrypto3-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl3-udeb - ssl shared library - udeb (udeb) libssl3t64 - Secure Sockets Layer toolkit - shared libraries openssl - Secure Sockets Layer toolkit - cryptographic utility openssl-provider-fips - Secure Sockets Layer toolkit - cryptographic utility openssl-provider-legacy - Secure Sockets Layer toolkit - cryptographic utility Closes: 1130650 Changes: openssl (3.5.5-1~deb13u2) trixie-security; urgency=medium . * CVE-2026-2673 ("OpenSSL TLS 1.3 server may choose unexpected key agreement group") (Closes: #1130650). * CVE-2026-28387 ("Potential use-after-free in DANE client code") * CVE-2026-28389 ("Possible NULL dereference when processing CMS KeyAgreeRecipientInfo") * CVE-2026-28390 ("Possible NULL dereference when processing CMS KeyTransportRecipient Info") * CVE-2026-31789 ("Heap buffer overflow in hexadecimal conversion") * CVE-2026-31790 ("Incorrect failure handling in RSA KEM RSASVE encapsulation") Checksums-Sha1: 898f7713e6cf92d01ed894eb8723b4a6946230cd 1550700 libcrypto3-udeb_3.5.5-1~deb13u2_armhf.udeb e7f93c8d7ed8f549f1d32eaead42e216ddbd407a 2567064 libssl-dev_3.5.5-1~deb13u2_armhf.deb bff9e37a86d945b3a0b093c577a0dda96993b03c 316984 libssl3-udeb_3.5.5-1~deb13u2_armhf.udeb e1cf4798134803eafff8709c232e86b55b7076e5 5871880 libssl3t64-dbgsym_3.5.5-1~deb13u2_armhf.deb 38ea86aae5ea3fbfa32b956772cff34b6a754fee 1991580 libssl3t64_3.5.5-1~deb13u2_armhf.deb 503e07c64a320f40bdc318e81575503367a25f3b 742064 openssl-dbgsym_3.5.5-1~deb13u2_armhf.deb 283e7f205a357cc98be6d549e0c88357324d50a0 1573280 openssl-provider-fips-dbgsym_3.5.5-1~deb13u2_armhf.deb f1cde7a7e5ebc8264bb029db76ab419f26e1c2ca 877508 openssl-provider-fips_3.5.5-1~deb13u2_armhf.deb a690bc83b92b1611b88d34c9c57ea6b25bfcc6af 94876 openssl-provider-legacy-dbgsym_3.5.5-1~deb13u2_armhf.deb a304501c29162170c9afd049c49bd6eda3b9b396 302796 openssl-provider-legacy_3.5.5-1~deb13u2_armhf.deb bce3f0fb583bf6137f1b042bdf13fe22f96e5bfd 8655 openssl_3.5.5-1~deb13u2_armhf-buildd.buildinfo 97ea7d1809eb3d2b80c8ec411e26318acd44f030 1467228 openssl_3.5.5-1~deb13u2_armhf.deb Checksums-Sha256: 504978e3a9022dff38faf1a630f5d4b5569a3663fdf343236392b05754a71b3e 1550700 libcrypto3-udeb_3.5.5-1~deb13u2_armhf.udeb 62151b12ea6c9c6defe6b5f094019da8bb72ad73678b07a81a53c185a656106e 2567064 libssl-dev_3.5.5-1~deb13u2_armhf.deb 5faad0aad28c7fd1bc3192fde692ce41ce79996749f3eb3ee2013aa9f88dc458 316984 libssl3-udeb_3.5.5-1~deb13u2_armhf.udeb 0f7cda352df92ae3a5487d60d6101e5357fdbdc020d9d7a62b820f367b904acc 5871880 libssl3t64-dbgsym_3.5.5-1~deb13u2_armhf.deb 4d0f9f04be2153c9b515eb2208a68d97dd4f0ea6c52fbb775677fa2b6f894b9b 1991580 libssl3t64_3.5.5-1~deb13u2_armhf.deb 8744afd32674b3dce9eb02a5ea4738c1d8b2494b59fd4e5a241340a68dbbb69f 742064 openssl-dbgsym_3.5.5-1~deb13u2_armhf.deb e2b2c5fbae802edaf9fdfacf8231a08f0d3898b7740b58c327fe2b54f183305d 1573280 openssl-provider-fips-dbgsym_3.5.5-1~deb13u2_armhf.deb 0e64253bcd17a2770c4da308931998f362ca259b68e49832b14f2919979c5659 877508 openssl-provider-fips_3.5.5-1~deb13u2_armhf.deb b765527d25d48d2f30f05767dd3055fee7b446b5a024231e4b3aba5e078dada3 94876 openssl-provider-legacy-dbgsym_3.5.5-1~deb13u2_armhf.deb 035a5343b7d66ee8a3752e61053a261b4210db0d3cc7f963999dccb072d5e370 302796 openssl-provider-legacy_3.5.5-1~deb13u2_armhf.deb a2646fe220fb657b94d3fc826afd96646c27f8030d8a4d6dce20ae8a52b7a545 8655 openssl_3.5.5-1~deb13u2_armhf-buildd.buildinfo 4b45415fe46cc8baeaecb395989e31e307d914965df2920c647f1c7b47ff6c39 1467228 openssl_3.5.5-1~deb13u2_armhf.deb Files: c8813a80719708b93a338f1b3595a39b 1550700 debian-installer optional libcrypto3-udeb_3.5.5-1~deb13u2_armhf.udeb c1b3bad57dbf827678a585e11be04d17 2567064 libdevel optional libssl-dev_3.5.5-1~deb13u2_armhf.deb 24d5cc6b8134daefcf209d87bca62bb4 316984 debian-installer optional libssl3-udeb_3.5.5-1~deb13u2_armhf.udeb 9517ad8fdb602e1641f7a878358852c8 5871880 debug optional libssl3t64-dbgsym_3.5.5-1~deb13u2_armhf.deb 2fef4b05aa9de84b1a46f0a0118d226e 1991580 libs optional libssl3t64_3.5.5-1~deb13u2_armhf.deb 74987abc2c5a91b64d8040c5bdc816b8 742064 debug optional openssl-dbgsym_3.5.5-1~deb13u2_armhf.deb fa9aca5ee90f561fa9575d1f24b9f915 1573280 debug optional openssl-provider-fips-dbgsym_3.5.5-1~deb13u2_armhf.deb 4206ee819364a7e67fe80ca7e475161a 877508 utils optional openssl-provider-fips_3.5.5-1~deb13u2_armhf.deb 6a5991b941db629ba5010aaa9890fefa 94876 debug optional openssl-provider-legacy-dbgsym_3.5.5-1~deb13u2_armhf.deb 098957745d1d27a3a1880f93c869c9c8 302796 utils optional openssl-provider-legacy_3.5.5-1~deb13u2_armhf.deb 303150d999b5fefbb2b20659d2d59dab 8655 utils optional openssl_3.5.5-1~deb13u2_armhf-buildd.buildinfo b14c94e635d90d66ded8a8b788ab2398 1467228 utils optional openssl_3.5.5-1~deb13u2_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpxWVfktWxVoKRwGgJ7tNDw2WyRsFAmnP4uIACgkQJ7tNDw2W yRui3BAAv11W0ngZSGIhtCtD+7yIicUazRkHDDxyyWiFKBMg8WTt5TTDH1iEqXR5 o69F2ruAKBcb6qLhHhhfgq2xJpi/mP1rmv1kLfVcZLg05voN2DoKu1Oyrg6gR8UW rKQKdMzmne20foikvehNS0Ly+oSI8J0Hkvis335i7V7R6l3rW62MhgsJtPsEJaw8 AeZ3flm5uEsEOfFUAObqhG6nOe5yT8UpSK2FM1SaFi7fGEM0v8cGSIbTiA6XEjUy bM1x6umRK+NkGJGdnZIyBhbenSrJ1mfGiIqIbjASL3ZgJ3YqOwpUQj/RiE+wQr5R jL+dWHrPunWgsg6AAbmnr3enQNKEverm6l0xPo7Q3O9ElKdxFujpPeFKsq5XBVz5 EttIEUzhtqXEWt/QiG02xw7xkSRnpPh3IjuWnHdNnd/tLv5qNXzRB4V8WndA52eJ 5DBXhwj7Nw32+B1ErloawcX5sO71ozNgDh2loZiSngkj2czy1jXI+l6msw/oPJWY JkLAFbUqopQwy9matl70sfOxTlqKUj0zvDsgbb01BSTMbQKuJ22x5pwJb1Bit0I/ wqAwZIfkK9xT80yTZc8NxXikCJrXRzmf0o1IT3YJpzBPyko/DZqGs65TjOdCJ9Pg Lbi6dR6Ew+2OuzlHErzvFtYgYAplBNMZiwHzYm1VzWxI7ALXZ8k= =Pd99 -----END PGP SIGNATURE-----