[ubuntu/resolute-updates] openssl 3.5.5-1ubuntu3.6 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Tue Sep 29 19:02:18 UTC 2026


openssl (3.5.5-1ubuntu3.6) resolute-security; urgency=medium

  * SECURITY UPDATE: Excessive Memory Allocation in Relative CRLDP Processing
    - debian/patches/CVE-2026-35189.patch: Defer computation of relative CRLDP
      names in crypto/x509/v3_crld.c, crypto/x509/v3_purp.c,
      crypto/x509/x509_vfy.c, include/crypto/x509.h.
    - CVE-2026-35189
  * SECURITY UPDATE: QUIC Unvalidated Amplification Credit may be Over
    Accounted
    - debian/patches/CVE-2026-35191-01.patch: don't double count full databgram
      length on unvalidated connections in ssl/quic/quic_port.c,
      ssl/quic/quic_rx_depack.c.
    - debian/patches/CVE-2026-35191-02.patch: Add a test to check for quic
      unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-03.patch: fixup! don't double count full
      databgram length on unvalidated connections in ssl/quic/quic_rx_depack.c.
    - debian/patches/CVE-2026-35191-04.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-05.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-06.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-07.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-08.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-09.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - debian/patches/CVE-2026-35191-10.patch: fixup! Add a test to check for
      quic unvalidated credit in test/quicapitest.c.
    - CVE-2026-35191
  * SECURITY UPDATE: Timing Side-Channel in Scalar Multiplication for Non-NIST
    EC Curves
    - debian/patches/CVE-2026-54872.patch: ec: make ossl_ec_scalar_mul_ladder()
      scalar padding constant time in crypto/bn/bn_intern.c,
      crypto/ec/ec_mult.c, include/crypto/bn.h.
    - CVE-2026-54872
  * SECURITY UPDATE: Non-Constant-Time SM2 Scalar Multiplication on ARM64 and
    RISC-V
    - debian/patches/CVE-2026-54875.patch: Make the ecp_sm2p256 scalar
      multiplication constant time in crypto/ec/ecp_sm2p256.c.
    - CVE-2026-54875
  * SECURITY UPDATE: Out-of-Bounds Access After SSL_set_SSL_CTX() During a
    Handshake
    - debian/patches/CVE-2026-72897-1.patch: Fix out-of-bounds valid_flags
      access after SSL_set_SSL_CTX() in ssl/ssl_lib.c.
    - debian/patches/CVE-2026-72897-2.patch: Add regression tests for the
      SSL_set_SSL_CTX() sigalg state in test/sslapitest.c.
    - debian/patches/CVE-2026-72897-3.patch: fixup! Fix out-of-bounds
      valid_flags access after SSL_set_SSL_CTX() in ssl/ssl_lib.c.
    - CVE-2026-72897
  * SECURITY UPDATE: QUIC Connection-Level Flow Control is Not Enforced for
    Streams
    - debian/patches/CVE-2026-75804-1.patch: CVE-2026-75804 QUIC connection-
      level flow control not enforced, remote memory exhaustion in
      ssl/quic/quic_fc.c.
    - debian/patches/CVE-2026-75804-2.patch: test verifies the connection level
      RX flow control window is enforced. in test/quic_fc_test.c.
    - CVE-2026-75804
  * SECURITY UPDATE: NULL Pointer Dereference in CMP Client Revocation Response
    Handling
    - debian/patches/CVE-2026-75805-1.patch: Guard comparison when values are
      NULL in crypto/cmp/cmp_client.c.
    - debian/patches/CVE-2026-75805-2.patch: Add test for CVE-2026-75805 in
      test/cmp_client_test.c.
    - CVE-2026-75805
  * SECURITY UPDATE: Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes
    DoS
    - debian/patches/CVE-2026-75806.patch: TLS: Reject undersized TLS 1.2 AEAD
      records before AEAD processing in ssl/record/methods/tls1_meth.c,
      test/recordlentest.c.
    - CVE-2026-75806
  * SECURITY UPDATE: Timing Side-Channel in SM2 Signature Generation
    - debian/patches/CVE-2026-77696.patch: sm2: make sm2_sig_gen() constant time
      in crypto/ec/ec_mult.c, crypto/sm2/sm2_sign.c.
    - CVE-2026-77696
  * SECURITY UPDATE: DTLS Retransmits Handshake Messages From a Stale Buffer
    Offset
    - debian/patches/CVE-2026-84782.patch: dtls: reset init_off before
      retransmitting a message in ssl/d1_lib.c, ssl/statem/statem_dtls.c,
      test/dtlstest.c.
    - CVE-2026-84782
  * SECURITY UPDATE: QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
    - debian/patches/CVE-2026-84784-1.patch: CVE-2026-84784 QUIC: unbounded
      RETIRE_CONNECTION_ID backlog (memory DoS) in ssl/quic/quic_channel.c.
    - debian/patches/CVE-2026-84784-2.patch: CVE-2026-84784 QUIC: unbounded
      RETIRE_CONNECTION_ID backlog (memory DoS) in test/radix/quic_ops.c,
      test/radix/quic_tests.c.
    - CVE-2026-84784

Date: 2026-09-23 12:21:42.601466+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.6
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list