[DSA 6412-1] botan3 security update

Aron Xu <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6412-1                   [email protected]
https://www.debian.org/security/                                  Aron Xu
August 05, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : botan3
CVE ID         : CVE-2026-44378
Debian Bug     : 

Multiple security issues were discovered in Botan, a C++ cryptography
library, which could result in denial of service, certificate validation
bypass or authentication bypass.

These issues have been addressed by updating botan3 to the new upstream
release 3.12.0. As a consequence this update changes the SONAME of the
shared library, and the runtime library package is renamed from
libbotan-3-7 to libbotan-3-12. No package in the stable distribution links
against the library, so no other packages in trixie are affected by this
change.

The libbotan-3-7 package is no longer built and will not be removed
automatically on upgrade if it had been installed manually. Locally built
or third-party software linking against libbotan-3-7 needs to be rebuilt
against libbotan-3-12, after which the old library package can be removed.

For the stable distribution (trixie), this problem has been fixed in
version 3.12.0+dfsg-2~deb13u1.

We recommend that you upgrade your botan3 packages.

For the detailed security status of botan3 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/botan3

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmpynXoACgkQ+GQ1dHE8
m67C0wgAieGZ5mSXwJ0cSYzKk8uKp7KdaqARuQl+6Hhe9TyNyd2xqjRd+xAzqNSt
aqWf0wvK3JigkqjsNrzyiv8OiPG1iSHv7seZjHu+NIkakQhoKGhhoRymYIlZ/Qc7
jb4j+exjRK9tMuuAsFWYccLYC+d47abyCoo+WxxB+0g8Wfpdl1z8Iq0O0q81dPxY
6jzzPowJamRp8+RMPRgrRbyT8P+chyP7q8HK8qhFhfk/xeTVSMhau5XVNhOT5PA+
NnxeRR+I8w9KZW2lsJ9WOPOuCemi5V35s2+zDFOc8KQELbXJKAHft3GoFBVBveCA
4HCFOCiIXsSnfh10vrF3E0nBFYyGFg==
=rxjF
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.