This bug was fixed in the package openssl - 4.0.3-1ubuntu1

---------------
openssl (4.0.3-1ubuntu1) stonking; urgency=medium

  * Merge with Debian experimental (LP: #2167826). Remaining changes:
    - Use perl:native in the autopkgtest for installability on i386.
    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl
    - Disable LTO with which the codebase is generally incompatible
      (LP #2058017)
    - Default config reads crypto-config and /etc/ssl/openssl.cnf.d dropins
    - Don't enable or package anything FIPS (LP #2087955)
    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)
    - Enable CPU jitter fluctuations
    - fips patches (debian/patches/fips):
      - crypto: Add kernel FIPS mode detection
      - crypto: Automatically use the FIPS provider...
      - apps/speed: Omit unavailable algorithms in FIPS mode
      - apps: pass -propquery arg to the libctx DRBG fetches
      - test: Ensure encoding runs with the correct context...
      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)
        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH
        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE
      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS
        provider
      - Fallback to default provider when FIPS provider is missing.

openssl (4.0.3-1) experimental; urgency=medium

  * Import 4.0.3
    - CVE-2026-84782 ("DTLS Retransmits Handshake Messages From a Stale Buffer
      Offset")
    - CVE-2026-35189 ("Memory Allocation in Relative CRLDP Processing")
    - CVE-2026-35191 ("QUIC Unvalidated Amplification Credit may be Over
      Accounted")
    - CVE-2026-42772 ("Potential CPU DoS via O(n^2) Fragment Reassembly in 
QUIC")
    - CVE-2026-54872 ("Timing Side-Channel in Scalar Multiplication for Non-NIST
      EC Curves")
    - CVE-2026-54873 ("QUIC STREAM Fragment Metadata DoS")
    - CVE-2026-54875 ("Non-Constant-Time SM2 Scalar Multiplication on ARM64 and
      RISC-V")
    - CVE-2026-72897 ("Out-of-Bounds Access After SSL_set_SSL_CTX() During a
      Handshake")
    - CVE-2026-75804 ("QUIC Connection-Level Flow Control is Not Enforced for
      Streams")
    - CVE-2026-75805 ("NULL Pointer Dereference in CMP Client Revocation
      Response Handling")
    - CVE-2026-75806 ("Unauthenticated and Undersized DTLS 1.2 AEAD Record
      Causes DoS")
    - CVE-2026-77696 ("Timing Side-Channel in SM2 Signature Generation")
    - CVE-2026-84783 ("Use-After-Free in X.509 Extension Cache Under Concurrent 
Use")
    - CVE-2026-84784 ("QUIC: Unbounded RETIRE_CONNECTION_ID Backlog")

openssl (4.0.2-1) experimental; urgency=medium

  * Import 4.0.2
    - CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
      INITIAL Packet")
    - CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
    - CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
      protectionAlg")
    - CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
      a Missing Certificate")
    - CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
      Epoch")
    - CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
      Validation")
    - CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
    - CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
      Exhaustion")
    - CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
      EVP_Cipher()") (Closes: #1145172)
    - CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
      Queue") (Closes: #1144615)
    - CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking") 
(Closes: #1143841)

 -- Ravi Kant Sharma <[email protected]>  Fri, 02 Oct 2026
12:25:40 +0200

** Changed in: openssl (Ubuntu)
       Status: In Progress => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-14456

** CVE added: https://cve.org/CVERecord?id=CVE-2026-14457

** CVE added: https://cve.org/CVERecord?id=CVE-2026-18798

** CVE added: https://cve.org/CVERecord?id=CVE-2026-35189

** CVE added: https://cve.org/CVERecord?id=CVE-2026-35191

** CVE added: https://cve.org/CVERecord?id=CVE-2026-42772

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54872

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54873

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54874

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54875

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54876

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63072

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63073

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63074

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63075

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63076

** CVE added: https://cve.org/CVERecord?id=CVE-2026-72897

** CVE added: https://cve.org/CVERecord?id=CVE-2026-75803

** CVE added: https://cve.org/CVERecord?id=CVE-2026-75804

** CVE added: https://cve.org/CVERecord?id=CVE-2026-75805

** CVE added: https://cve.org/CVERecord?id=CVE-2026-75806

** CVE added: https://cve.org/CVERecord?id=CVE-2026-77696

** CVE added: https://cve.org/CVERecord?id=CVE-2026-84782

** CVE added: https://cve.org/CVERecord?id=CVE-2026-84783

** CVE added: https://cve.org/CVERecord?id=CVE-2026-84784

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167826

Title:
  please merge openssl 4.0.3-1 into stonking

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2167826/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to