-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 03 Apr 2026 12:05:32 +0200 Source: openssl Binary: libcrypto3-udeb libssl-dev libssl3-udeb libssl3t64 libssl3t64-dbgsym openssl openssl-dbgsym openssl-provider-fips openssl-provider-fips-dbgsym openssl-provider-legacy openssl-provider-legacy-dbgsym Architecture: s390x Version: 3.5.5-1~deb13u2 Distribution: trixie-security Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Sebastian Andrzej Siewior Description: libcrypto3-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl3-udeb - ssl shared library - udeb (udeb) libssl3t64 - Secure Sockets Layer toolkit - shared libraries openssl - Secure Sockets Layer toolkit - cryptographic utility openssl-provider-fips - Secure Sockets Layer toolkit - cryptographic utility openssl-provider-legacy - Secure Sockets Layer toolkit - cryptographic utility Closes: 1130650 Changes: openssl (3.5.5-1~deb13u2) trixie-security; urgency=medium . * CVE-2026-2673 ("OpenSSL TLS 1.3 server may choose unexpected key agreement group") (Closes: #1130650). * CVE-2026-28387 ("Potential use-after-free in DANE client code") * CVE-2026-28389 ("Possible NULL dereference when processing CMS KeyAgreeRecipientInfo") * CVE-2026-28390 ("Possible NULL dereference when processing CMS KeyTransportRecipient Info") * CVE-2026-31789 ("Heap buffer overflow in hexadecimal conversion") * CVE-2026-31790 ("Incorrect failure handling in RSA KEM RSASVE encapsulation") Checksums-Sha1: 0d1a1f701f7c1509323be6267a3885d60eb18253 1594892 libcrypto3-udeb_3.5.5-1~deb13u2_s390x.udeb 7b1605aca513db4b4533b9157d45358353f487fb 2564080 libssl-dev_3.5.5-1~deb13u2_s390x.deb 4559fa694a4379255f594ff4defa55209f7e0c3b 347100 libssl3-udeb_3.5.5-1~deb13u2_s390x.udeb a03e1834000c801611e2ef18e6c7a9c963d0049c 5915924 libssl3t64-dbgsym_3.5.5-1~deb13u2_s390x.deb 432c4fddd4d987ba180d581b522627b851d4244f 2034864 libssl3t64_3.5.5-1~deb13u2_s390x.deb 690f4c93082285f2435034e734e2ed29a0613d83 749800 openssl-dbgsym_3.5.5-1~deb13u2_s390x.deb 9dac6470fadd659828a7fe99a914e6f38f6fec4a 1594952 openssl-provider-fips-dbgsym_3.5.5-1~deb13u2_s390x.deb c491ff6b02eed1d064067137b07526dba2aa1729 785452 openssl-provider-fips_3.5.5-1~deb13u2_s390x.deb c66c3663f8a674ad810a15ba665af80e4c75d1bc 96608 openssl-provider-legacy-dbgsym_3.5.5-1~deb13u2_s390x.deb ee290504bb9e0703728e6c16787ddcb8448251ca 308656 openssl-provider-legacy_3.5.5-1~deb13u2_s390x.deb 588622f5d921d33b6a6c97f187ddc1b41e4cf134 8651 openssl_3.5.5-1~deb13u2_s390x-buildd.buildinfo 169c284885bca6360221cf9546814832df12ca89 1488176 openssl_3.5.5-1~deb13u2_s390x.deb Checksums-Sha256: d2255a3baeb65095857e2a96ff115a04f8bf39d5dfc7533d13389ae2beb81a46 1594892 libcrypto3-udeb_3.5.5-1~deb13u2_s390x.udeb 2a1caf14f8d69e7cd777feb7034e30c6937067775bc88767f8535f5feb67dcdd 2564080 libssl-dev_3.5.5-1~deb13u2_s390x.deb e07dce0a74ce14d7954bffe9d95c91e57a69949e3a28cea2d01595022fca0197 347100 libssl3-udeb_3.5.5-1~deb13u2_s390x.udeb 74346106901a8053ee3d57efb2f5b15984ca13e1a38e8eafb387a6c5e7cdc2e7 5915924 libssl3t64-dbgsym_3.5.5-1~deb13u2_s390x.deb 0b4ba9b712eb0f6cbc17c62768e551bc641d8b6c0035e5585c6abfe1746af026 2034864 libssl3t64_3.5.5-1~deb13u2_s390x.deb ed9383daa4d85fa5765dfb13d50d3333244f8f6a5ba0bf37091d84f1327d2601 749800 openssl-dbgsym_3.5.5-1~deb13u2_s390x.deb 1ac058df8ac68509ccbda7d35937049762bd1eae4ed7bd6ef548212c142e2927 1594952 openssl-provider-fips-dbgsym_3.5.5-1~deb13u2_s390x.deb 33d7edbf57f85e56a592ce0fd74dddfb2771062b89cde98a1fc4e05844d26264 785452 openssl-provider-fips_3.5.5-1~deb13u2_s390x.deb 0a7a64d3dba4553cc4d9b966385a53de887eb0c3513f7e8c09e7782fbf78ef2b 96608 openssl-provider-legacy-dbgsym_3.5.5-1~deb13u2_s390x.deb 5379ca6280e45632fe2a872c1b7c8baea39ae62014a35b0589bd98801b0e06ed 308656 openssl-provider-legacy_3.5.5-1~deb13u2_s390x.deb 7310e91241ca90d43c5ea538bf169e1863c4f4e7b1a0ae6bd235e29d5926e229 8651 openssl_3.5.5-1~deb13u2_s390x-buildd.buildinfo 6a7a48f01be00e1a489b45294dc41dbb401f591fb09a1c5c96012dbf346731c9 1488176 openssl_3.5.5-1~deb13u2_s390x.deb Files: a1618349c1a32931316aa240199ec136 1594892 debian-installer optional libcrypto3-udeb_3.5.5-1~deb13u2_s390x.udeb 4df2ab59f29971a5071a225d57a0a6e5 2564080 libdevel optional libssl-dev_3.5.5-1~deb13u2_s390x.deb fe679975428e9bf815101812f7b7524e 347100 debian-installer optional libssl3-udeb_3.5.5-1~deb13u2_s390x.udeb b4e7c007d6831dfb51072a2469998fef 5915924 debug optional libssl3t64-dbgsym_3.5.5-1~deb13u2_s390x.deb 6055aa3d076cf37a707aa888c5ffcaf1 2034864 libs optional libssl3t64_3.5.5-1~deb13u2_s390x.deb 8acb42f7cf9dfc8d4546563a2942f4c9 749800 debug optional openssl-dbgsym_3.5.5-1~deb13u2_s390x.deb db1380ed01d8ab4cf82e089475151183 1594952 debug optional openssl-provider-fips-dbgsym_3.5.5-1~deb13u2_s390x.deb 4126d9dcac15f202551c887a31143414 785452 utils optional openssl-provider-fips_3.5.5-1~deb13u2_s390x.deb 08dbc7565183a3f46fbb29e7359f481f 96608 debug optional openssl-provider-legacy-dbgsym_3.5.5-1~deb13u2_s390x.deb 1b35d89250615658ef04821cb0c4846c 308656 utils optional openssl-provider-legacy_3.5.5-1~deb13u2_s390x.deb 8cc924f11c135a1b2f5339b3643293c3 8651 utils optional openssl_3.5.5-1~deb13u2_s390x-buildd.buildinfo 8a54a331636302150bbf0389eec96d9a 1488176 utils optional openssl_3.5.5-1~deb13u2_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENly2ANlpa4eeqnluvVOPI7pYNpgFAmnP4A4ACgkQvVOPI7pY NpiXrw/8CwEezrxIlMKE4NOwGIxtRikKGWLfWnKRKbuc+qhsxTf+new6d9mx5adC gtENhwCxnYgxBh54peXt7cxmjw0lTVrqKcSuKwBOZedkCTpFij7fkueN5Yni1rX4 y2UkL+YtNaJclEfjoh2g8EZYE2NqOGTiZ8kgi49HWYKDZccbzOpY5LYCIpJWymT5 ahgnSrUO/pfSQe72ceNvM1bMkqf9iI/sMk3HaeY3dUydynW5pJF+Aax7l54TUJRO XrvSI1yTr5WE91ZeTeL8zWGCXm/0eI2sl2wMJOfMz+f8DAGbVXa8O3etxT0oKYUI we8gJH8uwdvs9TKfjBYXQLnyG55Qsh5GcSgvK6TWpXU7x+ppW7ab7q6viuaNmovb Dsk2FtPFE8rUb046nFTzPwd1w2V1yHCelJQIHwewPWuCGdqxywHAwLE02hCIgktT 2GywuzDMn8Tn8vRyQKPqH9p6/X2pVV0ks4PYiPKfzUxgvATcOBiGYUnyE9jO9CKC dfbivlZAs7WLUUJcgVGrj5kUCQ/4mqYVR5bd4+u+wdbQby9zgqtvvsMlvcJ0yRtH /Hc9Iw9v8yeAt8AGIDmC1Apk/uj7SPW4g3tO0Ue3RDgbhPgNeIU9cUks+JX6nWPa C3VFUYRvPf6Z8CymMaDs+UzweV8rZFsYx+vbE6pm0BqrP/1BHdg= =+9sh -----END PGP SIGNATURE-----