-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 14 Feb 2026 07:53:42 +0100 Source: gnutls28 Architecture: source Version: 3.8.9-3+deb13u2 Distribution: trixie-security Urgency: high Maintainer: Debian GnuTLS Maintainers Changed-By: Andreas Metzler Changes: gnutls28 (3.8.9-3+deb13u2) trixie-security; urgency=high . * libgnutls: Fix name constraint processing performance issue Verifying certificates with pathological amounts of name constraints could lead to a denial of service attack via resource exhaustion. Reworked processing algorithms exhibit better performance characteristics. Reported by Tim Scheckenbach. [Fixes: GNUTLS-SA-2026-02-09-2, CVSS: medium] [CVE-2025-14831] Checksums-Sha1: 6cd6d276a79599ad5cc38c102508086567e239d1 3271 gnutls28_3.8.9-3+deb13u2.dsc 4bacfbfcba06b67e91bbd3535c275b04ef89a61f 6847364 gnutls28_3.8.9.orig.tar.xz 2d96a7aa8a204014dc40b14030b9120edad27174 833 gnutls28_3.8.9.orig.tar.xz.asc b9ef2dba0eda2197ef141ffca7398004a352b55e 102436 gnutls28_3.8.9-3+deb13u2.debian.tar.xz 04cab15da66e81a68d4876a49efb1b4a0b525d20 6984 gnutls28_3.8.9-3+deb13u2_source.buildinfo Checksums-Sha256: b7aeed97b22870fae0587f531561d78cd8093ed5f432f30cd79a37ac94be10b0 3271 gnutls28_3.8.9-3+deb13u2.dsc 69e113d802d1670c4d5ac1b99040b1f2d5c7c05daec5003813c049b5184820ed 6847364 gnutls28_3.8.9.orig.tar.xz 7631d47762865d4ef494492cca794cf0fe6a8be892a4aa02f362ae29006d3054 833 gnutls28_3.8.9.orig.tar.xz.asc e61d47849b1d5ce7e7bbfe8f9dc82e6b48479dfc8b78248d4daa0038307a0d26 102436 gnutls28_3.8.9-3+deb13u2.debian.tar.xz e9018408ffdac1f106baacd819a0088e46e1f78ef6d7c3ca59d3fefe008fe31c 6984 gnutls28_3.8.9-3+deb13u2_source.buildinfo Files: b19a9223c1c6479c3fcc9d304b74b2c2 3271 libs optional gnutls28_3.8.9-3+deb13u2.dsc 33f4c800c20af2983c45223a803da865 6847364 libs optional gnutls28_3.8.9.orig.tar.xz 70e70e5e8822e3649e5e07e3cb87c5cd 833 libs optional gnutls28_3.8.9.orig.tar.xz.asc 48d8aeef68292c3a98fced25452def4d 102436 libs optional gnutls28_3.8.9-3+deb13u2.debian.tar.xz 36e687b234a513c865f459f3206904cc 6984 libs optional gnutls28_3.8.9-3+deb13u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmmR/bIACgkQpU8BhUOC FITdkw//W9QzL+6Q0M+n4sy5nrpTFGuc3uqltkUozHVBG82r0gUbjBqrVrK3RDYp hBsrW541IjHgVb6dlXC8EM0jm7ASmiA4ucc6i3WN6E9xbTqqBcmiTtpeLhsX39AN 9/2eSCufedRZg419lKtSk/WZBfi3GwVpWd9IIKfspEegznEdt3LWIhlfKfE1HJex t/P7dhre6f12tQyqC7aGySsYUc0PTMpA18O8f9etKBdfDlO/zvSoT2IIJzaVY17K KWJqkZlpKMGWXZKOz7rZie4cai3HOPel4l+8sCGy7rGBKblyI/bdHs0xWixvxf8w 7o9M+qpdCLBn9zJ1hfNjaHdRCnjagu0Dux0ZL0qWjcTZxrx57RoNiaPSM3hm8w4p KeQrWIwBYoEdP4sgA9TigLjU32rwQG04USYkl7ZorMiAahv81hXUTHPqGhH1ogi5 Q8oJs9w+2MGIkBD0VquLFkVyP3+ERAOuj+F5XNIZ8RHb18kNGu52RZvskortXTiZ T3V1IwiXCl8rkGK9qWOZ/0cNUvnYhokb4wZJUUswMFnmUSgm/MeS7LwWWMx9oQJZ 7PGb3QfMjX7ZPrmrMhpI39jsz6dYa2Dn2f93KUOiCSeeuOA2zVCL90wnmg0yLOnD ZycZ7fnylEJqkmlTHPYXMICV6lMea/SJe7myveApMEcTZJWz19U= =z381 -----END PGP SIGNATURE-----