This did not pass d-release so here is a forward of the original message
-attachment:

Package: release.debian.org
Control: affects -1 + src:openssl
User: [email protected]
Usertags: pu
Tags: trixie
Severity: normal

This is an update to the latest LTS version. All CVE related fixes are
already fixed as of last upload via -security.
It contains fixes for the stable release which don't qualify as
security/CVE related but can be annoying and worth fixing.

There was an email on openssl-package list
        
https://alioth-lists.debian.net/pipermail/pkg-openssl-devel/2026-July/009511.html

where someone did ask for an update because the current version might be
affected by a memory fragmentation attack. Upstream does not consider
this as a CVE worthy but the release contains some hardening against it.

The diff is rather huge again. Last time there was a lot of code
reformating. This time it is again code reformating as hex data in data
structures had one value per line (now it is about ten).

The 3.6.3 version is already in unstable and should contain all (and
probably more) of those changes that went into 3.5.7. Here I am not
aware of any fallout.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

Sebastian

Reply via email to