This bug was fixed in the package openssl - 4.0.3-1ubuntu1
---------------
openssl (4.0.3-1ubuntu1) stonking; urgency=medium
* Merge with Debian experimental (LP: #2167826). Remaining changes:
- Use perl:native in the autopkgtest for installability on i386.
- Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl
- Disable LTO with which the codebase is generally incompatible
(LP #2058017)
- Default config reads crypto-config and /etc/ssl/openssl.cnf.d dropins
- Don't enable or package anything FIPS (LP #2087955)
- Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)
- Enable CPU jitter fluctuations
- fips patches (debian/patches/fips):
- crypto: Add kernel FIPS mode detection
- crypto: Automatically use the FIPS provider...
- apps/speed: Omit unavailable algorithms in FIPS mode
- apps: pass -propquery arg to the libctx DRBG fetches
- test: Ensure encoding runs with the correct context...
- Add Ubuntu-specific defines to help FIPS certification (LP #2073991)
+ UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH
+ UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE
- Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS
provider
- Fallback to default provider when FIPS provider is missing.
openssl (4.0.3-1) experimental; urgency=medium
* Import 4.0.3
- CVE-2026-84782 ("DTLS Retransmits Handshake Messages From a Stale Buffer
Offset")
- CVE-2026-35189 ("Memory Allocation in Relative CRLDP Processing")
- CVE-2026-35191 ("QUIC Unvalidated Amplification Credit may be Over
Accounted")
- CVE-2026-42772 ("Potential CPU DoS via O(n^2) Fragment Reassembly in
QUIC")
- CVE-2026-54872 ("Timing Side-Channel in Scalar Multiplication for Non-NIST
EC Curves")
- CVE-2026-54873 ("QUIC STREAM Fragment Metadata DoS")
- CVE-2026-54875 ("Non-Constant-Time SM2 Scalar Multiplication on ARM64 and
RISC-V")
- CVE-2026-72897 ("Out-of-Bounds Access After SSL_set_SSL_CTX() During a
Handshake")
- CVE-2026-75804 ("QUIC Connection-Level Flow Control is Not Enforced for
Streams")
- CVE-2026-75805 ("NULL Pointer Dereference in CMP Client Revocation
Response Handling")
- CVE-2026-75806 ("Unauthenticated and Undersized DTLS 1.2 AEAD Record
Causes DoS")
- CVE-2026-77696 ("Timing Side-Channel in SM2 Signature Generation")
- CVE-2026-84783 ("Use-After-Free in X.509 Extension Cache Under Concurrent
Use")
- CVE-2026-84784 ("QUIC: Unbounded RETIRE_CONNECTION_ID Backlog")
openssl (4.0.2-1) experimental; urgency=medium
* Import 4.0.2
- CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
INITIAL Packet")
- CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
- CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
protectionAlg")
- CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
a Missing Certificate")
- CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
Epoch")
- CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
Validation")
- CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
- CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
Exhaustion")
- CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
EVP_Cipher()") (Closes: #1145172)
- CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
Queue") (Closes: #1144615)
- CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking")
(Closes: #1143841)
-- Ravi Kant Sharma <[email protected]> Fri, 02 Oct 2026
12:25:40 +0200
** Changed in: openssl (Ubuntu)
Status: In Progress => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-14456
** CVE added: https://cve.org/CVERecord?id=CVE-2026-14457
** CVE added: https://cve.org/CVERecord?id=CVE-2026-18798
** CVE added: https://cve.org/CVERecord?id=CVE-2026-35189
** CVE added: https://cve.org/CVERecord?id=CVE-2026-35191
** CVE added: https://cve.org/CVERecord?id=CVE-2026-42772
** CVE added: https://cve.org/CVERecord?id=CVE-2026-54872
** CVE added: https://cve.org/CVERecord?id=CVE-2026-54873
** CVE added: https://cve.org/CVERecord?id=CVE-2026-54874
** CVE added: https://cve.org/CVERecord?id=CVE-2026-54875
** CVE added: https://cve.org/CVERecord?id=CVE-2026-54876
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63072
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63073
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63074
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63075
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63076
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72897
** CVE added: https://cve.org/CVERecord?id=CVE-2026-75803
** CVE added: https://cve.org/CVERecord?id=CVE-2026-75804
** CVE added: https://cve.org/CVERecord?id=CVE-2026-75805
** CVE added: https://cve.org/CVERecord?id=CVE-2026-75806
** CVE added: https://cve.org/CVERecord?id=CVE-2026-77696
** CVE added: https://cve.org/CVERecord?id=CVE-2026-84782
** CVE added: https://cve.org/CVERecord?id=CVE-2026-84783
** CVE added: https://cve.org/CVERecord?id=CVE-2026-84784
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167826
Title:
please merge openssl 4.0.3-1 into stonking
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2167826/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs