[ubuntu/resolute-proposed] openssl 3.5.5-1ubuntu3 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Apr 7 20:15:36 UTC 2026


openssl (3.5.5-1ubuntu3) resolute; urgency=medium

  * SECURITY UPDATE: OpenSSL TLS 1.3 server may choose unexpected key
    agreement group
    - debian/patches/CVE-2026-2673.patch: fix group tuple handling in
      DEFAULT expansion in doc/man3/SSL_CTX_set1_curves.pod,
      ssl/t1_lib.c, test/tls13groupselection_test.c.
    - CVE-2026-2673
  * SECURITY UPDATE: NULL pointer dereference when processing an OCSP
    response
    - debian/patches/CVE-2026-28387.patch: dane_match_cert() should
      X509_free() on ->mcert instead of OPENSSL_free() in
      crypto/x509/x509_vfy.c.
    - CVE-2026-28387
  * SECURITY UPDATE: NULL Pointer Dereference When Processing a Delta CRL
    - debian/patches/CVE-2026-28388-1.patch: fix NULL Dereference When
      Delta CRL Lacks CRL Number Extension in crypto/x509/x509_vfy.c.
    - debian/patches/CVE-2026-28388-2.patch: Added test in test/*.
    - CVE-2026-28388
  * SECURITY UPDATE: Possible NULL dereference when processing CMS
    KeyAgreeRecipientInfo
    - debian/patches/CVE-2026-28389.patch: Fix NULL deref in
      [ec]dh_cms_set_shared_info in crypto/cms/cms_dh.c,
      crypto/cms/cms_ec.c.
    - CVE-2026-28389
  * SECURITY UPDATE: Possible NULL Dereference When Processing CMS
    KeyTransportRecipientInfo
    - debian/patches/CVE-2026-28390.patch: Fix NULL deref in
      rsa_cms_decrypt in crypto/cms/cms_rsa.c.
    - CVE-2026-28390
  * SECURITY UPDATE: Heap buffer overflow in hexadecimal conversion
    - debian/patches/CVE-2026-31789.patch: avoid possible buffer overflow
      in buf2hex conversion in crypto/o_str.c.
    - CVE-2026-31789
  * SECURITY UPDATE: Incorrect failure handling in RSA KEM RSASVE
    encapsulation
    - debian/patches/CVE-2026-31790-1.patch: validate RSA_public_encrypt()
      result in RSASVE in providers/implementations/kem/rsa_kem.c.
    - debian/patches/CVE-2026-31790-2.patch: test RSA_public_encrypt()
      result in RSASVE in test/evp_extra_test.c.
    - CVE-2026-31790

Date: Tue, 07 Apr 2026 08:05:56 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3
-------------- next part --------------
Format: 1.8
Date: Tue, 07 Apr 2026 08:05:56 -0400
Source: openssl
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.5.5-1ubuntu3
Distribution: resolute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 openssl (3.5.5-1ubuntu3) resolute; urgency=medium
 .
   * SECURITY UPDATE: OpenSSL TLS 1.3 server may choose unexpected key
     agreement group
     - debian/patches/CVE-2026-2673.patch: fix group tuple handling in
       DEFAULT expansion in doc/man3/SSL_CTX_set1_curves.pod,
       ssl/t1_lib.c, test/tls13groupselection_test.c.
     - CVE-2026-2673
   * SECURITY UPDATE: NULL pointer dereference when processing an OCSP
     response
     - debian/patches/CVE-2026-28387.patch: dane_match_cert() should
       X509_free() on ->mcert instead of OPENSSL_free() in
       crypto/x509/x509_vfy.c.
     - CVE-2026-28387
   * SECURITY UPDATE: NULL Pointer Dereference When Processing a Delta CRL
     - debian/patches/CVE-2026-28388-1.patch: fix NULL Dereference When
       Delta CRL Lacks CRL Number Extension in crypto/x509/x509_vfy.c.
     - debian/patches/CVE-2026-28388-2.patch: Added test in test/*.
     - CVE-2026-28388
   * SECURITY UPDATE: Possible NULL dereference when processing CMS
     KeyAgreeRecipientInfo
     - debian/patches/CVE-2026-28389.patch: Fix NULL deref in
       [ec]dh_cms_set_shared_info in crypto/cms/cms_dh.c,
       crypto/cms/cms_ec.c.
     - CVE-2026-28389
   * SECURITY UPDATE: Possible NULL Dereference When Processing CMS
     KeyTransportRecipientInfo
     - debian/patches/CVE-2026-28390.patch: Fix NULL deref in
       rsa_cms_decrypt in crypto/cms/cms_rsa.c.
     - CVE-2026-28390
   * SECURITY UPDATE: Heap buffer overflow in hexadecimal conversion
     - debian/patches/CVE-2026-31789.patch: avoid possible buffer overflow
       in buf2hex conversion in crypto/o_str.c.
     - CVE-2026-31789
   * SECURITY UPDATE: Incorrect failure handling in RSA KEM RSASVE
     encapsulation
     - debian/patches/CVE-2026-31790-1.patch: validate RSA_public_encrypt()
       result in RSASVE in providers/implementations/kem/rsa_kem.c.
     - debian/patches/CVE-2026-31790-2.patch: test RSA_public_encrypt()
       result in RSASVE in test/evp_extra_test.c.
     - CVE-2026-31790
Checksums-Sha1:
 faa86856aa418b782b0da091c07081bb12d1c7f7 2905 openssl_3.5.5-1ubuntu3.dsc
 11ccec7dbc2edd9881603c347f65b25e155722cc 80844 openssl_3.5.5-1ubuntu3.debian.tar.xz
 77eccfebf353ea87cbfe057bcadc6cfae4679244 6339 openssl_3.5.5-1ubuntu3_source.buildinfo
Checksums-Sha256:
 0cf775dbba03c288ba125c4fdfc61d9f66c134747371cc6684d986dc17639fbc 2905 openssl_3.5.5-1ubuntu3.dsc
 609a26242bfc01fb1791c9d5bc23242fd12a89db9e7692fb62aa09086750c4fe 80844 openssl_3.5.5-1ubuntu3.debian.tar.xz
 3df42e13d59088baf784bab4ed6c8fa10a203a128ebcce11aabe5ffc25a5beae 6339 openssl_3.5.5-1ubuntu3_source.buildinfo
Files:
 efa5b984b3e939c9156c6a1fcec99440 2905 utils optional openssl_3.5.5-1ubuntu3.dsc
 2b276892b456106b958c7e0d1d725e07 80844 utils optional openssl_3.5.5-1ubuntu3.debian.tar.xz
 dc5440104cb91212de763a7e7df19883 6339 utils optional openssl_3.5.5-1ubuntu3_source.buildinfo
Original-Maintainer: Debian OpenSSL Team <pkg-openssl-devel at alioth-lists.debian.net>


More information about the Resolute-changes mailing list