- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Sebastian Andrzej Siewior
- Date:
- 2026-09-12 08:07:24 UTC
- Severity:
- normal
- Tags:
This is an update to the latest LTS version. All CVE related fixes are already fixed as of last upload via -security. It contains fixes for the stable release which don't qualify as security/CVE related but can be annoying and worth fixing. There was an email on openssl-package list https://alioth-lists.debian.net/pipermail/pkg-openssl-devel/2026-July/009511.html where someone did ask for an update because the current version might be affected by a memory fragmentation attack. Upstream does not consider this as a CVE worthy but the release contains some hardening against it. The diff is rather huge again. Last time there was a lot of code reformating. This time it is again code reformating as hex data in data structures had one value per line (now it is about ten). The 3.6.3 version is already in unstable and should contain all (and probably more) of those changes that went into 3.5.7. Here I am not aware of any fallout. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable Sebastian
This did not pass d-release so here is a forward of the original message -attachment: Package: release.debian.org Control: affects -1 + src:openssl User: release.debian.org@packages.debian.org Usertags: pu Tags: trixie Severity: normal This is an update to the latest LTS version. All CVE related fixes are already fixed as of last upload via -security. It contains fixes for the stable release which don't qualify as security/CVE related but can be annoying and worth fixing. There was an email on openssl-package list https://alioth-lists.debian.net/pipermail/pkg-openssl-devel/2026-July/009511.html where someone did ask for an update because the current version might be affected by a memory fragmentation attack. Upstream does not consider this as a CVE worthy but the release contains some hardening against it. The diff is rather huge again. Last time there was a lot of code reformating. This time it is again code reformating as hex data in data structures had one value per line (now it is about ten). The 3.6.3 version is already in unstable and should contain all (and probably more) of those changes that went into 3.5.7. Here I am not aware of any fallout. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable Sebastian
package release.debian.org tags 1142499 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: openssl Version: 3.5.7-1~deb13u1 Explanation: new upstream release
package release.debian.org tags 1142499 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: openssl Version: 3.5.7-1~deb13u1 Explanation: new upstream release
This update was released as part of 13.7.