-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Sep 2025 21:18:35 +0200 Source: openssl Architecture: source Version: 3.5.1-1+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Debian OpenSSL Team <pkg-openssl-devel@alioth-lists.debian.net> Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc> Changes: openssl (3.5.1-1+deb13u1) trixie-security; urgency=medium . * CVE-2025-9230 (Out-of-bounds read & write in RFC 3211 KEK Unwrap) * CVE-2025-9231 (Timing side-channel in SM2 algorithm on 64 bit ARM) * CVE-2025-9232 (Out-of-bounds read in HTTP client no_proxy handling) Checksums-Sha1: bf97b766bc9dbe222b95a4dc985d093685763156 2669 openssl_3.5.1-1+deb13u1.dsc c2473d27ebfd33e1e08f9fbf1ef303f848edd8dd 53158817 openssl_3.5.1.orig.tar.gz c398db721ed8b40e454d46b738ac9f942a554edf 833 openssl_3.5.1.orig.tar.gz.asc 0f284d435eb2d071338fd0abdf8d3521019bbaa0 51876 openssl_3.5.1-1+deb13u1.debian.tar.xz Checksums-Sha256: b803cf40ee3c1e29c15924b15600ea072923262b3dbc27f94cb57240c8e342d0 2669 openssl_3.5.1-1+deb13u1.dsc 529043b15cffa5f36077a4d0af83f3de399807181d607441d734196d889b641f 53158817 openssl_3.5.1.orig.tar.gz 6d5d22d4b908aabbfc96c5d04a993b6233506d67a14e184c816fee3e15782c80 833 openssl_3.5.1.orig.tar.gz.asc 8afc153ffa4a49861fb23bb38439257e7cf4de04b569324606c0bb802018cdb6 51876 openssl_3.5.1-1+deb13u1.debian.tar.xz Files: f910d489b7acb2e4e0ac6c58d577f47a 2669 utils optional openssl_3.5.1-1+deb13u1.dsc 562a4e8d14ee5272f677a754b9c1ca5c 53158817 utils optional openssl_3.5.1.orig.tar.gz 2abb17965a65a6f1b533d0bd3a1aa526 833 utils optional openssl_3.5.1.orig.tar.gz.asc 578fbb0a2edb6c0fd4af8bac379908ab 51876 utils optional openssl_3.5.1-1+deb13u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmjW8MQACgkQBWQfF1cS +lug8gv8DdPJhPjVAIJRjPhRcTJLh+SoymmnC/Nmr2UubcWfhmRUoEIoCVcIj6vZ a1FgBou0v856ipNabJ6e7rdBCHr043sdxAtYXmlf8hnPLqVSRHnOQzOrXk9tswjC wsi/lf6M7++3rV3QOIetNtD1KLWPvWGSZ/eT7TilTeFTrDaccyRuPI8o+M8UlyMD rt8z/ULQWBCkYCUHZgKd4kA2Sjpx2L9rN5J8XQjv7/6rgvRLarDZFi0yBBv7Kmx8 C0lYjvWhMGWqiXFjDJ1UT8wbd9JsBcPWih1HsRXz4WDVg4HxOKhizMBEM5rWT1l0 F8eiKgdl1ZzkfD1QS8uRymQl/qzM5/+j7JUjy3zVpfbOxy1QBGIy41fZFZVH+aDF B+ZLs+wOlYRDlUtGNiCTE4tEBggbb9yGI5jxRhJwIAZ9nrmX5v+pv2XHtmmDUsPA XNXuWkBc0EUy58qA+YE58e2IZEB03SNtFSatlIyc+NarvEQ+jpDDQwjkMHlnkVQx 2OZD3zlv =nW/x -----END PGP SIGNATURE-----