[DSA 6465-1] openssl security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6465-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
August 25, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : openssl
CVE ID         : CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-54874
                 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075
                 CVE-2026-63076 CVE-2026-75803
Debian Bug     : 1144615 1145172

Multiple vulnerabilities have been discovered in OpenSSL, a Secure
Sockets Layer toolkit, which may result in denial of service.

Additional details can be found in the upstream advisories:
https://openssl-library.org/news/secadv/20260813.txt
https://openssl-library.org/news/secadv/20260825.txt

For the stable distribution (trixie), these problems have been fixed in
version 3.5.7-1~deb13u2.

We recommend that you upgrade your openssl packages.

For the detailed security status of openssl please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/openssl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqN5alfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QBqRAAlXIilJWwjS0VS1pgroaCFUNGhL1HrTsBIIrnnrWTUOeD19fFLvvcVK5B
j1UaT/jurxSp6Bkre7NrQFzLlXk6xvRWTR2dxv9K1q29lYgPwpVjfO25kdQ2LWeg
0n0qA4Kb394Evtf9lmb3KMNrrRJHc9DmuXZDQWAjsNRwVxBEaJ+yN9Im92CcQQQb
CUgVYzlx+mvBfPTGgStTFJjMXT/pTaVz+WDHbfEc5WM8tRe3YYb+e+/vOdA4jrEv
UKdH1M+fNg1gB7+cCr8QyTQiTMvz2BxwBuI7jlK67FFZL322SqON4chQRXleWp86
imyBANOP4dRdMV1aYGT38VZYjoURwuvLR77ZhyLe1c927YcIkXe11K0HMwq9DeXv
o+TQQTf1qJN8Zd0sQuz88/d6T9jtzRgFvNkZpiXXy3nQrKnE0FAfZuGCyniiie9b
VipvzWLxfpeEH9TW9hotwCVyv395RRaWM6m8UuQI4J+3yVTUY4S+nO4aHo5Wi5HN
WeYxaFZSKYTUlsjAGMgYGm5aH4TtAFoHxzTTzsvvArKPDpFukZH4Ux+t9adydwTZ
KRxmHmEWcLYKchZksLymvOCKrG57LTAqJi+CVi+oJAc23RqYyZy1tEdB8hSQ6s2S
sTk0pcwjB5xk4BZXdDr/8nmqivlfJA3eFDO0K9P/l9CFK280MQw=
=IuuF
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.