This bug was fixed in the package openssl3 - 3.5.5-1ubuntu6

---------------
openssl3 (3.5.5-1ubuntu6) stonking; urgency=medium

  * Sync security patches from Resolute (LP: #2169720)
    - from version 3.5.5-1ubuntu3.6 and 3.5.5-1ubuntu3.7
  * Add runtime scope to d/README.source (LP #2167636)
  * Drop Uploaders and Vcs-* from d/control (LP #2167636)
  * SECURITY UPDATE: Excessive Memory Allocation in Relative CRLDP Processing
    - debian/patches/CVE-2026-35189.patch: Defer computation of relative CRLDP
      names in crypto/x509/v3_crld.c, crypto/x509/v3_purp.c,
      crypto/x509/x509_vfy.c, include/crypto/x509.h.
    - CVE-2026-35189
  * SECURITY UPDATE: QUIC Unvalidated Amplification Credit may be Over
    Accounted
    - debian/patches/CVE-2026-35191-01.patch: don't double count full databgram
      length on unvalidated connections in ssl/quic/quic_port.c,
      ssl/quic/quic_rx_depack.c.
    - debian/patches/CVE-2026-35191-02.patch: Add a test to check for quic
      unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-03.patch: fixup! don't double count full
      databgram length on unvalidated connections in ssl/quic/quic_rx_depack.c.
    - debian/patches/CVE-2026-35191-04.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-05.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-06.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-07.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-08.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-09.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-10.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - CVE-2026-35191
  * SECURITY UPDATE: Timing Side-Channel in Scalar Multiplication for Non-NIST
    EC Curves
    - debian/patches/CVE-2026-54872.patch: ec: make ossl_ec_scalar_mul_ladder()
      scalar padding constant time in crypto/bn/bn_intern.c,
      crypto/ec/ec_mult.c, include/crypto/bn.h.
    - CVE-2026-54872
  * SECURITY UPDATE: Non-Constant-Time SM2 Scalar Multiplication on ARM64 and
    RISC-V
    - debian/patches/CVE-2026-54875.patch: Make the ecp_sm2p256 scalar
      multiplication constant time in crypto/ec/ecp_sm2p256.c.
    - CVE-2026-54875
  * SECURITY UPDATE: Out-of-Bounds Access After SSL_set_SSL_CTX() During a
    Handshake
    - debian/patches/CVE-2026-72897-1.patch: Fix out-of-bounds valid_flags
      access after SSL_set_SSL_CTX() in ssl/ssl_lib.c.
    - debian/patches/CVE-2026-72897-2.patch: Add regression tests for the
      SSL_set_SSL_CTX() sigalg state in test/sslapitest.c.
    - debian/patches/CVE-2026-72897-3.patch: fixup! Fix out-of-bounds
      valid_flags access after SSL_set_SSL_CTX() in ssl/ssl_lib.c.
    - CVE-2026-72897
  * SECURITY UPDATE: QUIC Connection-Level Flow Control is Not Enforced for
    Streams
    - debian/patches/CVE-2026-75804-1.patch: CVE-2026-75804 QUIC connection-
      level flow control not enforced, remote memory exhaustion in
      ssl/quic/quic_fc.c.
    - debian/patches/CVE-2026-75804-2.patch: test verifies the connection level
      RX flow control window is enforced. in test/quic_fc_test.c.
    - CVE-2026-75804
  * SECURITY UPDATE: NULL Pointer Dereference in CMP Client Revocation Response
    Handling
    - debian/patches/CVE-2026-75805-1.patch: Guard comparison when values are
      NULL in crypto/cmp/cmp_client.c.
    - debian/patches/CVE-2026-75805-2.patch: Add test for CVE-2026-75805 in
      test/cmp_client_test.c.
    - CVE-2026-75805
  * SECURITY UPDATE: Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes
    DoS
    - debian/patches/CVE-2026-75806.patch: TLS: Reject undersized TLS 1.2 AEAD
      records before AEAD processing in ssl/record/methods/tls1_meth.c,
      test/recordlentest.c.
    - CVE-2026-75806
  * SECURITY UPDATE: Timing Side-Channel in SM2 Signature Generation
    - debian/patches/CVE-2026-77696.patch: sm2: make sm2_sig_gen() constant time
      in crypto/ec/ec_mult.c, crypto/sm2/sm2_sign.c.
    - CVE-2026-77696
  * SECURITY UPDATE: DTLS Retransmits Handshake Messages From a Stale Buffer
    Offset
    - debian/patches/CVE-2026-84782.patch: dtls: reset init_off before
      retransmitting a message in ssl/d1_lib.c, ssl/statem/statem_dtls.c,
      test/dtlstest.c.
    - CVE-2026-84782
  * SECURITY UPDATE: QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
    - debian/patches/CVE-2026-84784-1.patch: CVE-2026-84784 QUIC: unbounded
      RETIRE_CONNECTION_ID backlog (memory DoS) in ssl/quic/quic_channel.c.
    - debian/patches/CVE-2026-84784-2.patch: CVE-2026-84784 QUIC: unbounded
      RETIRE_CONNECTION_ID backlog (memory DoS) in test/radix/quic_ops.c,
      test/radix/quic_tests.c.
    - CVE-2026-84784
  * SECURITY UPDATE: Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
    - debian/patches/CVE-2026-42772-pre1.patch: Add a red-black tree
      implementation in crypto/build.info, crypto/rbtree/build.info,
      crypto/rbtree/rbtree.c, doc/internal/man7/ossl_rbtree.pod,
      include/internal/ossl_rbtree.h, ssl/build.info, test/build.info,
      test/ossl_rbtree_test.c, test/recipes/02-test_rbtree.t,
      util/missingcrypto-internal.txt.
    - debian/patches/CVE-2026-42772-pre2.patch: quic: move the RXE definition to
      a local header in ssl/quic/quic_record_rx.c,
      ssl/quic/quic_record_rx_local.h.
    - debian/patches/CVE-2026-42772-pre3.patch: test: cover the packet pinning
      path of QUIC stream reassembly in test/quic_stream_test.c.
    - debian/patches/CVE-2026-42772-pre4.patch: test: cover a long lagging read
      of packet backed stream data in test/quic_stream_test.c.
    - debian/patches/CVE-2026-42772-pre5.patch: test: reassemble small out of
      order frames and check the bytes in test/quic_stream_test.c.
    - debian/patches/CVE-2026-42772-pre6.patch: Add ossl_list_TYPE_join(head,
      tail) function in doc/internal/man3/DEFINE_LIST_OF.pod,
      include/internal/list.h, test/list_test.c.
    - debian/patches/CVE-2026-42772.patch: New implementation of stream
      reassembly for QUIC. in include/internal/quic_stream.h,
      include/internal/quic_strm_reas.h, ssl/quic/build.info,
      ssl/quic/quic_channel.c, ssl/quic/quic_rstream.c,
      ssl/quic/quic_strm_reas.c, test/quic_stream_test.c, test/quic_txp_test.c.
    - CVE-2026-42772
  * SECURITY UPDATE: QUIC STREAM Fragment Metadata DoS
    - debian/patches/CVE-2026-54873.patch: Limit packet buffer overhead to ~64kB
      per stream. in include/internal/quic_predef.h,
      include/internal/quic_stream.h, include/internal/quic_strm_reas.h,
      ssl/quic/quic_channel.c, ssl/quic/quic_channel_local.h,
      ssl/quic/quic_rstream.c, ssl/quic/quic_strm_reas.c,
      test/quic_stream_test.c, test/quic_txp_test.c.
    - debian/patches/CVE-2026-54873-post1.patch: Enforce final size for streams.
      in include/internal/quic_stream.h, ssl/quic/quic_channel.c,
      ssl/quic/quic_rstream.c, ssl/quic/quic_strm_reas.c,
      test/quic_stream_test.c.
    - debian/patches/CVE-2026-54873-post2.patch: Add explicit tests to check
      some typical stream reassembly situation in test/quic_stream_test.c.
    - debian/patches/CVE-2026-54873-post3.patch: test: cover FIN final size
      against buffered data in test/quic_stream_test.c.
    - debian/patches/CVE-2026-54873-post4.patch: test: cover zero length read of
      a QUIC rstream in test/quic_stream_test.c.
    - debian/patches/CVE-2026-54873-post5.patch: test: cover two sided overlap
      of direct tail chunk in test/quic_stream_test.c.
    - debian/patches/CVE-2026-54873-post6.patch: test: cover cleansing of
      dropped duplicate bytes in test/quic_stream_test.c.
    - debian/patches/CVE-2026-54873-post7.patch: test: cover
      sc_data_trim_right() function in test/quic_stream_test.c.
    - debian/patches/CVE-2026-54873-post8.patch: make ch_cleanup() just safe
      enough to be called by quic_stream_test in ssl/quic/quic_channel.c.
    - CVE-2026-54873

 -- Ravi Kant Sharma <[email protected]>  Tue, 06 Oct 2026
17:33:28 +0200

** Changed in: openssl3 (Ubuntu)
       Status: In Progress => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-35189

** CVE added: https://cve.org/CVERecord?id=CVE-2026-35191

** CVE added: https://cve.org/CVERecord?id=CVE-2026-42772

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54872

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54873

** CVE added: https://cve.org/CVERecord?id=CVE-2026-54875

** CVE added: https://cve.org/CVERecord?id=CVE-2026-72897

** CVE added: https://cve.org/CVERecord?id=CVE-2026-75804

** CVE added: https://cve.org/CVERecord?id=CVE-2026-75805

** CVE added: https://cve.org/CVERecord?id=CVE-2026-75806

** CVE added: https://cve.org/CVERecord?id=CVE-2026-77696

** CVE added: https://cve.org/CVERecord?id=CVE-2026-84782

** CVE added: https://cve.org/CVERecord?id=CVE-2026-84784

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169720

Title:
  Bring security patches from Resolute

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl3/+bug/2169720/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to