-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 14 Feb 2026 15:49:14 +0100 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx30 libgnutlsxx30-dbgsym Architecture: amd64 Version: 3.7.9-2+deb12u6 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx30 - GNU TLS library - C++ runtime library Closes: 1121146 Changes: gnutls28 (3.7.9-2+deb12u6) bookworm-security; urgency=high . * Add patch for CVE-2025-9820 / GNUTLS-SA-2025-11-18 from 3.8.11. Closes: #1121146 * libgnutls: Fix name constraint processing performance issue Verifying certificates with pathological amounts of name constraints could lead to a denial of service attack via resource exhaustion. Reworked processing algorithms exhibit better performance characteristics. Reported by Tim Scheckenbach. [Fixes: GNUTLS-SA-2026-02-09-2, CVSS: medium] [CVE-2025-14831] Checksums-Sha1: 01cf1262bf73e4842ddc88014d23e41711c69d30 893948 gnutls-bin-dbgsym_3.7.9-2+deb12u6_amd64.deb 0376da1f2ece6f4b6aa1cab2a3ce3fb5f9e0d288 641564 gnutls-bin_3.7.9-2+deb12u6_amd64.deb cb9b4c3907ae94ec9eb591fe1e926921340acd4b 11456 gnutls28_3.7.9-2+deb12u6_amd64-buildd.buildinfo d6e2fd6734083736e38a02f8aa25875c936a92be 258380 guile-gnutls-dbgsym_3.7.9-2+deb12u6_amd64.deb 3da0c0b335b73720d96206d9f0adefe8ca951e2e 463232 guile-gnutls_3.7.9-2+deb12u6_amd64.deb ba21274ca1e12b1fff216734cd37a0270a03767f 91960 libgnutls-dane0-dbgsym_3.7.9-2+deb12u6_amd64.deb dc4763f63dea63d01d17b1f47da6138ca356cd62 407196 libgnutls-dane0_3.7.9-2+deb12u6_amd64.deb 622bc3178d253119c17ccc5479826c0256b4c2f0 92300 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u6_amd64.deb c6fdd9648c9779db5a1536984c2bec16ae09a88e 407160 libgnutls-openssl27_3.7.9-2+deb12u6_amd64.deb 9138d3175f11de38432b20e256481fa5e188c0c6 1355780 libgnutls28-dev_3.7.9-2+deb12u6_amd64.deb 7d0d8cbe1ec511d85a2d1ffa0a5a9bcd70ae70e7 2121284 libgnutls30-dbgsym_3.7.9-2+deb12u6_amd64.deb 3907251f7a289a27526182f5431d1f77e5ff6891 1408284 libgnutls30_3.7.9-2+deb12u6_amd64.deb 89bb6a844b260e927f7d7c064425be0415b61c49 49732 libgnutlsxx30-dbgsym_3.7.9-2+deb12u6_amd64.deb 60798c73da572b0cbd7fa4d281a490414bfbc001 14400 libgnutlsxx30_3.7.9-2+deb12u6_amd64.deb Checksums-Sha256: 28e2691dadccfcd30ab765672bc7b4c786783f1857089a3ea6eca5231f281f40 893948 gnutls-bin-dbgsym_3.7.9-2+deb12u6_amd64.deb a56089bba5c6615e89161e1f37ac1c38a62bdd1ab484bd325403173016300388 641564 gnutls-bin_3.7.9-2+deb12u6_amd64.deb 41afd9ffd3c83ae359951453d3a2d964b1fee49d515a15aac12cd7f7a12cf774 11456 gnutls28_3.7.9-2+deb12u6_amd64-buildd.buildinfo 75af61e034431baaeb43fd1c46a82d60e8ea2ad26617f8bc32abe440225be5b6 258380 guile-gnutls-dbgsym_3.7.9-2+deb12u6_amd64.deb a6b4ef8fdefaa2644244b62dd9622d478f5a76335839e9946ed63fffe5a408a6 463232 guile-gnutls_3.7.9-2+deb12u6_amd64.deb 1dbeca7c310ac095f9b1cb26f928db24ce56a043fbc2c11c299ce9092e7b8722 91960 libgnutls-dane0-dbgsym_3.7.9-2+deb12u6_amd64.deb e4345b40d5bdde3c394ec9c411bc854229fe1088bdba69bcaf1b5d4ba6b7aae1 407196 libgnutls-dane0_3.7.9-2+deb12u6_amd64.deb 2c5c093dd0da75e2464e218b4642d77ed7930cd9bab7d8a8fd19b8581e56a2ba 92300 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u6_amd64.deb 1e1e54c0ce069424ef22b14c16e8af9db6a67648b62cacb28ac97fddb169c4e1 407160 libgnutls-openssl27_3.7.9-2+deb12u6_amd64.deb be2f81511bb8f071d3d12bef3a3b8dfebe70107c993608da6296960cda50696a 1355780 libgnutls28-dev_3.7.9-2+deb12u6_amd64.deb c198aec64a8330443c55a824aa499659a36ff82d0bd4cd20f1d78048d9d19654 2121284 libgnutls30-dbgsym_3.7.9-2+deb12u6_amd64.deb 10deacd86b6113c0cd679491aaf7b3416365ef407e56fe93d6009710a08811de 1408284 libgnutls30_3.7.9-2+deb12u6_amd64.deb b78bbb1d229796b60ee6219f8102d796aa613131851ea9c24eef482cce77ece3 49732 libgnutlsxx30-dbgsym_3.7.9-2+deb12u6_amd64.deb e22cc04c5b4f69db0a4b9f5d5e4835d0858a1ae850daadefe46ea7181b675ea3 14400 libgnutlsxx30_3.7.9-2+deb12u6_amd64.deb Files: cd98600b76d827ad361c7bb25fd3fbcd 893948 debug optional gnutls-bin-dbgsym_3.7.9-2+deb12u6_amd64.deb f329c17c2c5eb019d99a25c12159da25 641564 net optional gnutls-bin_3.7.9-2+deb12u6_amd64.deb a28aa8fa3ffe4c8ece1b01c9427ab603 11456 libs optional gnutls28_3.7.9-2+deb12u6_amd64-buildd.buildinfo 18c042f7e9f3a7c98eaf23e974d2273a 258380 debug optional guile-gnutls-dbgsym_3.7.9-2+deb12u6_amd64.deb e8a9ee609fd643d36035e043713bf8e5 463232 lisp optional guile-gnutls_3.7.9-2+deb12u6_amd64.deb fa98089822fb3e2bf01ace851c1c1faf 91960 debug optional libgnutls-dane0-dbgsym_3.7.9-2+deb12u6_amd64.deb e822423e9e012b54fdfdcae48e529367 407196 libs optional libgnutls-dane0_3.7.9-2+deb12u6_amd64.deb 28ef6842caf002ff24a66e5c623c32c4 92300 debug optional libgnutls-openssl27-dbgsym_3.7.9-2+deb12u6_amd64.deb 5f23663dd0e945d54096884711027d82 407160 libs optional libgnutls-openssl27_3.7.9-2+deb12u6_amd64.deb 58621d321a5a452a88bd1a19ad45bee1 1355780 libdevel optional libgnutls28-dev_3.7.9-2+deb12u6_amd64.deb 91f22c7bab8db22e1bd4bf060748fe18 2121284 debug optional libgnutls30-dbgsym_3.7.9-2+deb12u6_amd64.deb 7afeaa8f237567e315cbed9691bbd3a3 1408284 libs optional libgnutls30_3.7.9-2+deb12u6_amd64.deb 75511d3fb58106690662b7869f00e8d1 49732 debug optional libgnutlsxx30-dbgsym_3.7.9-2+deb12u6_amd64.deb 7d3aa8613a9edb2193c54cf094876e17 14400 libs optional libgnutlsxx30_3.7.9-2+deb12u6_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXNeYFUF3FbHcrtSeIy3Pg040HrAFAmmSBnoACgkQIy3Pg040 HrBHrBAAkrV0EusAVjmXE6syJuKfqtAV6SQYSXcQ22k3261mAE6Zpd4T6cVdD3eU v7rWPhPXhkN4R8e43xEP+jlbT7bnJJLUF58qFeNIl8wZ4y1WmovpDI4adM7VGPu8 2/ms+nygnwwnFindHPyIp4BsBhJpZ6WWnyB3wxWPai04wTq2o02Yp+H8hrrQI+er sUXaRtsYqUBE48LeCujfJq6ix/y50ErXCLTQMSybVt7UeWIlCv3E+HNz3DrpEi3C QJDO9MaaJVnO6wuDyss6DEmt8U9zucMXaYpezLwjqZ4tjBKuctwq0UoYuDu5+kLL yoNe3Pj5DoVw3vJllwimcxSzmEWW8bA2zSBDp2HvMKFFkCywEwpgBEcENl6o0th1 9Q6lmHXmGlbEev6wUTNRLqRq6C8o14/06i/HuKvD2zzY9TVu7Tvk9YeluR6FgA53 jbAJXyxvtp4XxL1Hbltkxp7I18X3610PjRV7zZ0d0n9+Yn+sEiEIk2nSCRlDztx5 xuTGn9/cTV7JBvW1CsyZNlzkxGzYvNsqmHCnOHstjc/MoWa6r8pTI76D2/qkIjBf SntZYV85JG3DheGUIeO7RXN/ioweLum8vOw882s15G4yVa6LGrQQ+V9ZZtTLJ4/B 3EotkOtOKseKaJHd20bcyA3X5U1s02PYNflIXk+IuqngEquPgSg= =Yl9K -----END PGP SIGNATURE-----