We believe that the bug you reported is fixed in the latest version of
bouncycastle, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1134386@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Emmanuel Bourg <ebourg@apache.org> (supplier of updated bouncycastle package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 28 Sep 2026 09:35:25 +0200
Source: bouncycastle
Architecture: source
Version: 1.86-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Emmanuel Bourg <ebourg@apache.org>
Closes: 1134195 1134196 1134343 1134386 1143536
Changes:
bouncycastle (1.86-1) unstable; urgency=medium
.
* New upstream release
- Fix CVE-2026-3505: unbounded AEAD chunk size in the OpenPGP v6 SEIPD
packet parser (Closes: #1134195)
- Fix CVE-2026-0636: LDAP injection in LDAPStoreHelper (Closes: #1134343)
- Fix CVE-2026-5588: the PKIX draft CompositeVerifier accepted an empty
signature sequence as valid (Closes: #1134196)
- Fix CVE-2026-5598: non-constant time comparisons risked leaking the
private key in FrodoKEM (Closes: #1134386)
- Fix the 32 further CVEs reported against 1.80, fixed upstream in 1.85
(Closes: #1143536)
- Refreshed the patches
- Updated the Maven poms
- libbcpg-java now depends on libbcutil-java
* Rewrote the watch file in the version 5 format
* Removed the obsolete exclusions in debian/copyright
* Removed the redundant Priority field
* Standards-Version updated to 4.7.4
Checksums-Sha1:
809e8ee70d187514a09a7b4377b4b2315246fed9 2461 bouncycastle_1.86-1.dsc
f6e48fbf7032a1c2b6cf79bfa7b70857437fe7ad 8086256 bouncycastle_1.86.orig.tar.xz
0cec97ab9063bf73b2935b7e4fa47ccdf036eab0 11248 bouncycastle_1.86-1.debian.tar.xz
a856fdc3f8ba9d798efca700ce8e5c95c6d89b70 15411 bouncycastle_1.86-1_source.buildinfo
Checksums-Sha256:
b509f702eab506cf5019d47a85eaed947a08be6b550fcbf2a26936f3533e10a3 2461 bouncycastle_1.86-1.dsc
ec425b70f99be7d5ed69ae73244d693ce03ce0e0f6128b8f8f8cd40862b63072 8086256 bouncycastle_1.86.orig.tar.xz
d4b75935401e3eb48dd8a2abff8c4236ef3666d37a72ed522f81dbfb62fd3359 11248 bouncycastle_1.86-1.debian.tar.xz
c26652b33c51f3c10f466206e78fd651454ec313d962e89cd66a4bf2af4a2e65 15411 bouncycastle_1.86-1_source.buildinfo
Files:
8686e04b846475719b887dcf6d3f00a4 2461 java optional bouncycastle_1.86-1.dsc
8a36bc6a6835ffffc4d791de4b6046eb 8086256 java optional bouncycastle_1.86.orig.tar.xz
f48d9cad94ff9d1427c2a79e559b103a 11248 java optional bouncycastle_1.86-1.debian.tar.xz
e37af3f7ab0132c5c9cbef771bd8eaf3 15411 java optional bouncycastle_1.86-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEEuM5N4hCA3PkD4WxA9RPEGeS50KwFAmq6GdkSHGVib3VyZ0Bh
cGFjaGUub3JnAAoJEPUTxBnkudCsnnIP/06MOPZF6Fx/67ZCcCBFKkbLL5K7edix
d2sLD9NcyDHiBxrpZ4c/csy1RLRuNTE+h5F1RYqV1DEqWkviDbFm2FtPs4z/g83F
PL1V6cgJqzsSwZ2PJdNAaMsC3LdXziIjI3+tGzlR/u9cI1mwa1hCa+YSEtS5NcUB
7mVfGDCUze2xg/O8UjW407MY1hYggjVtUxlpdP/woY/PDYMD3dqtD5Lv3E/h6wgm
GqcbBqZRTJdiaTfTVIn2I1Ykh9++8kvaK1xZL0lpErRVFWI2sGq6D8MPiboxFVI2
LBD1uAPBpWYw/Ga0N9sNMgqeekm0fKDMHn+vm6i7G8UUG62Ux0WO3xRLsWGH4SE1
F/W0q9TE8Wvd+mrkJ7QZgNF7QENAfTXIZBX+iApmd/Jktikg2dikAduP268Zr0wd
QUpaBuh/8DcwD3pEj+3+ORzVHhvTFLdT32JnNcb0uD+5+LzV2Tqh+pKZF9VckjYH
+1D4PG1+jkPxIO4WpjcQi2y/hS/fUgpjZpPxDSBc3MZUO4fOo0a7GSwRLs2CHX38
RFkPxVV6xRUP7v7aM+jRbXD/rAx1cfLQ+r9aqW7CdDz0NN7CsBPrwYR9fuXSvjIc
FsQ/gR5XaJ8Ggu8CxImV8D8f5KfrPjDhATkpVf2bjqJhxSEy2/3miJx+tp49Lipp
GkzZlop7cz8V
=rvq9
-----END PGP SIGNATURE-----