[ubuntu/resolute-updates] openssl 3.5.5-1ubuntu3.6 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Tue Sep 29 19:02:18 UTC 2026
openssl (3.5.5-1ubuntu3.6) resolute-security; urgency=medium
* SECURITY UPDATE: Excessive Memory Allocation in Relative CRLDP Processing
- debian/patches/CVE-2026-35189.patch: Defer computation of relative CRLDP
names in crypto/x509/v3_crld.c, crypto/x509/v3_purp.c,
crypto/x509/x509_vfy.c, include/crypto/x509.h.
- CVE-2026-35189
* SECURITY UPDATE: QUIC Unvalidated Amplification Credit may be Over
Accounted
- debian/patches/CVE-2026-35191-01.patch: don't double count full databgram
length on unvalidated connections in ssl/quic/quic_port.c,
ssl/quic/quic_rx_depack.c.
- debian/patches/CVE-2026-35191-02.patch: Add a test to check for quic
unvalidated credit in test/quicapitest.c.
- debian/patches/CVE-2026-35191-03.patch: fixup! don't double count full
databgram length on unvalidated connections in ssl/quic/quic_rx_depack.c.
- debian/patches/CVE-2026-35191-04.patch: fixup! Add a test to check for
quic unvalidated credit in test/quicapitest.c.
- debian/patches/CVE-2026-35191-05.patch: fixup! Add a test to check for
quic unvalidated credit in test/quicapitest.c.
- debian/patches/CVE-2026-35191-06.patch: fixup! Add a test to check for
quic unvalidated credit in test/quicapitest.c.
- debian/patches/CVE-2026-35191-07.patch: fixup! Add a test to check for
quic unvalidated credit in test/quicapitest.c.
- debian/patches/CVE-2026-35191-08.patch: fixup! Add a test to check for
quic unvalidated credit in test/quicapitest.c.
- debian/patches/CVE-2026-35191-09.patch: fixup! Add a test to check for
quic unvalidated credit in test/quicapitest.c.
- debian/patches/CVE-2026-35191-10.patch: fixup! Add a test to check for
quic unvalidated credit in test/quicapitest.c.
- CVE-2026-35191
* SECURITY UPDATE: Timing Side-Channel in Scalar Multiplication for Non-NIST
EC Curves
- debian/patches/CVE-2026-54872.patch: ec: make ossl_ec_scalar_mul_ladder()
scalar padding constant time in crypto/bn/bn_intern.c,
crypto/ec/ec_mult.c, include/crypto/bn.h.
- CVE-2026-54872
* SECURITY UPDATE: Non-Constant-Time SM2 Scalar Multiplication on ARM64 and
RISC-V
- debian/patches/CVE-2026-54875.patch: Make the ecp_sm2p256 scalar
multiplication constant time in crypto/ec/ecp_sm2p256.c.
- CVE-2026-54875
* SECURITY UPDATE: Out-of-Bounds Access After SSL_set_SSL_CTX() During a
Handshake
- debian/patches/CVE-2026-72897-1.patch: Fix out-of-bounds valid_flags
access after SSL_set_SSL_CTX() in ssl/ssl_lib.c.
- debian/patches/CVE-2026-72897-2.patch: Add regression tests for the
SSL_set_SSL_CTX() sigalg state in test/sslapitest.c.
- debian/patches/CVE-2026-72897-3.patch: fixup! Fix out-of-bounds
valid_flags access after SSL_set_SSL_CTX() in ssl/ssl_lib.c.
- CVE-2026-72897
* SECURITY UPDATE: QUIC Connection-Level Flow Control is Not Enforced for
Streams
- debian/patches/CVE-2026-75804-1.patch: CVE-2026-75804 QUIC connection-
level flow control not enforced, remote memory exhaustion in
ssl/quic/quic_fc.c.
- debian/patches/CVE-2026-75804-2.patch: test verifies the connection level
RX flow control window is enforced. in test/quic_fc_test.c.
- CVE-2026-75804
* SECURITY UPDATE: NULL Pointer Dereference in CMP Client Revocation Response
Handling
- debian/patches/CVE-2026-75805-1.patch: Guard comparison when values are
NULL in crypto/cmp/cmp_client.c.
- debian/patches/CVE-2026-75805-2.patch: Add test for CVE-2026-75805 in
test/cmp_client_test.c.
- CVE-2026-75805
* SECURITY UPDATE: Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes
DoS
- debian/patches/CVE-2026-75806.patch: TLS: Reject undersized TLS 1.2 AEAD
records before AEAD processing in ssl/record/methods/tls1_meth.c,
test/recordlentest.c.
- CVE-2026-75806
* SECURITY UPDATE: Timing Side-Channel in SM2 Signature Generation
- debian/patches/CVE-2026-77696.patch: sm2: make sm2_sig_gen() constant time
in crypto/ec/ec_mult.c, crypto/sm2/sm2_sign.c.
- CVE-2026-77696
* SECURITY UPDATE: DTLS Retransmits Handshake Messages From a Stale Buffer
Offset
- debian/patches/CVE-2026-84782.patch: dtls: reset init_off before
retransmitting a message in ssl/d1_lib.c, ssl/statem/statem_dtls.c,
test/dtlstest.c.
- CVE-2026-84782
* SECURITY UPDATE: QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
- debian/patches/CVE-2026-84784-1.patch: CVE-2026-84784 QUIC: unbounded
RETIRE_CONNECTION_ID backlog (memory DoS) in ssl/quic/quic_channel.c.
- debian/patches/CVE-2026-84784-2.patch: CVE-2026-84784 QUIC: unbounded
RETIRE_CONNECTION_ID backlog (memory DoS) in test/radix/quic_ops.c,
test/radix/quic_tests.c.
- CVE-2026-84784
Date: 2026-09-23 12:21:42.601466+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.6
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list