From foo@bar  Sun Aug 30 03:30:02 2026
Format: 1.8
Date: Tue, 25 Aug 2026 21:19:42 +0200
Source: openssl
Binary: libcrypto4-udeb libssl-dev libssl4 libssl4-dbgsym libssl4-udeb openssl openssl-dbgsym openssl-provider-fips openssl-provider-fips-dbgsym openssl-provider-legacy openssl-provider-legacy-dbgsym
Architecture: hurd-i386
Version: 4.0.2-1
Distribution: experimental
Urgency: medium
Maintainer: Debian GNU/Hurd Build Daemon <buildd_hurd-i386-ironforge@buildd.debian.org>
Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Description:
 libcrypto4-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb)
 libssl-dev - Secure Sockets Layer toolkit - development files
 libssl4    - Secure Sockets Layer toolkit - shared libraries
 libssl4-udeb - ssl shared library - udeb (udeb)
 openssl    - Secure Sockets Layer toolkit - cryptographic utility
 openssl-provider-fips - Secure Sockets Layer toolkit - cryptographic utility
 openssl-provider-legacy - Secure Sockets Layer toolkit - cryptographic utility
Closes: 1143841 1144615 1145172
Changes:
 openssl (4.0.2-1) experimental; urgency=medium
 .
   * Import 4.0.2
     - CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
       INITIAL Packet")
     - CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
     - CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
       protectionAlg")
     - CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
       a Missing Certificate")
     - CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
       Epoch")
     - CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
       Validation")
     - CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
     - CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
       Exhaustion")
     - CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
       EVP_Cipher()") (Closes: #1145172)
     - CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
       Queue") (Closes: #1144615)
     - CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking") (Closes: #1143841)
Checksums-Sha1:
 3a488932a48885743cdbd0c340e9501f6286889a 2033576 libcrypto4-udeb_4.0.2-1_hurd-i386.udeb
 e40b42c4f080f6d04a5133c9fdf0f086a063e198 3150628 libssl-dev_4.0.2-1_hurd-i386.deb
 d9f601f8cd9b3b45cf8784444ffdcd4af9f341a0 5090368 libssl4-dbgsym_4.0.2-1_hurd-i386.deb
 7669e83fc84fd199f69239e748080bb5e845a38b 472696 libssl4-udeb_4.0.2-1_hurd-i386.udeb
 407d34b18d196f385d0aa9cfc6f2373434dbd964 2529476 libssl4_4.0.2-1_hurd-i386.deb
 36855d05f2d48d1f11937c6779a4da5916b3f0c8 678648 openssl-dbgsym_4.0.2-1_hurd-i386.deb
 672d91cbb2852f7a5f4069bd32559915fbf7c1d7 1483328 openssl-provider-fips-dbgsym_4.0.2-1_hurd-i386.deb
 5a15fabfaff955a262317c6f644d309d62ae4a7b 1091708 openssl-provider-fips_4.0.2-1_hurd-i386.deb
 0baa00b2e6b569c66d441a260e46db58b0dbb47d 82572 openssl-provider-legacy-dbgsym_4.0.2-1_hurd-i386.deb
 c211d5f147c4dae60fef8bfec5ba89c768c60a3e 329716 openssl-provider-legacy_4.0.2-1_hurd-i386.deb
 23d7ed8dd79a40061a081126d1f58fa56436f63b 8915 openssl_4.0.2-1_hurd-i386.buildinfo
 b2a26334a38ee704a5ce02dc4e31203efe47b38d 1584100 openssl_4.0.2-1_hurd-i386.deb
Checksums-Sha256:
 0d8afa8fe3bd585e2fa817f1bda177418b87cbaa02971c5b2c6cd43745962d66 2033576 libcrypto4-udeb_4.0.2-1_hurd-i386.udeb
 09a89cc0f99ba4868f9e42eaae329e42533ff013549a612e2ddf0b5768407e1a 3150628 libssl-dev_4.0.2-1_hurd-i386.deb
 6c680a67e220e3c250f407c812e62a53eeeac117209de0a57171f12e97b5730c 5090368 libssl4-dbgsym_4.0.2-1_hurd-i386.deb
 16fee52f175749ebf401893212d7cdecd42df956b10538632ec28cdc6d4b4807 472696 libssl4-udeb_4.0.2-1_hurd-i386.udeb
 be1992634bcd994f6769fd6da2e1c73370ead27cb54223db104141c2e5b999a8 2529476 libssl4_4.0.2-1_hurd-i386.deb
 d69d07b7348cc99e60a341300617a9f7a83e0057a4704c8ca16c2d947c392b39 678648 openssl-dbgsym_4.0.2-1_hurd-i386.deb
 93d29bdb0ffbf1ebab1248907496ea4bb774028be1f9f0fe33fe1337f56c06d6 1483328 openssl-provider-fips-dbgsym_4.0.2-1_hurd-i386.deb
 97522b4b15fde6f6e560bdce61377aad06160badf2c39ea91349ec49646e2bea 1091708 openssl-provider-fips_4.0.2-1_hurd-i386.deb
 b8c48a956d423208ead2ec11c30e3ad25aa2e47a5e5227d0dc478dd1419ccf5d 82572 openssl-provider-legacy-dbgsym_4.0.2-1_hurd-i386.deb
 c0056ed3ba9aed86cc452da8cabda5527357a809f2bbb641f2f9e0bad6351718 329716 openssl-provider-legacy_4.0.2-1_hurd-i386.deb
 9278e94c3ef2ca6afc63bd95c447caef80daaa069d45e743b027225ff0022fc8 8915 openssl_4.0.2-1_hurd-i386.buildinfo
 4c37e09e673806d3c57deb96b1405ab6608638090c0c720bf1192161672ba71b 1584100 openssl_4.0.2-1_hurd-i386.deb
Files:
 053bdf234f0489177e8d301ac6f01db0 2033576 debian-installer optional libcrypto4-udeb_4.0.2-1_hurd-i386.udeb
 343c8c9ad03954f8240a2bde41c54a0a 3150628 libdevel optional libssl-dev_4.0.2-1_hurd-i386.deb
 1cf4e48a3cf3fd6dfcd47a2f002231f6 5090368 debug optional libssl4-dbgsym_4.0.2-1_hurd-i386.deb
 c17abcd629998cafe02a7be206de703a 472696 debian-installer optional libssl4-udeb_4.0.2-1_hurd-i386.udeb
 ecdb26e09ac279ebe585663614afb1eb 2529476 libs optional libssl4_4.0.2-1_hurd-i386.deb
 35c9e2d014c6660b218644dd5c88fd1a 678648 debug optional openssl-dbgsym_4.0.2-1_hurd-i386.deb
 a14d73b2723150c663d9e06cce6840c4 1483328 debug optional openssl-provider-fips-dbgsym_4.0.2-1_hurd-i386.deb
 6fdb0e7195087f0ef2a50962acf4ecf9 1091708 utils optional openssl-provider-fips_4.0.2-1_hurd-i386.deb
 2050cd014ea38e373efb570fdc947b6b 82572 debug optional openssl-provider-legacy-dbgsym_4.0.2-1_hurd-i386.deb
 031b9b2e6a8e1521833e7f5896e39664 329716 utils optional openssl-provider-legacy_4.0.2-1_hurd-i386.deb
 4265a99b72223606ca25f7df5a97f635 8915 utils optional openssl_4.0.2-1_hurd-i386.buildinfo
 bf84b8fbf106c8e06e52d91846c7a80a 1584100 utils optional openssl_4.0.2-1_hurd-i386.deb
Signed-By: buildd autosigning key ironforge <buildd_hurd-i386-ironforge@buildd.debian.org>

