New Debian openssl 3.0.17-1~deb12u3 fixes: This update addresses the following issues: 3.0.17-1~deb12u3 (Fri, 26 Sep 2025 20:59:22 +0200) * CVE-2025-9230 (Out-of-bounds read & write in RFC 3211 KEK Unwrap) * CVE-2025-9232 (Out-of-bounds read in HTTP client no_proxy handling)
--- mirror/ftp/pool/main/o/openssl/openssl_3.0.17-1~deb12u2.dsc +++ apt/ucs_5.2-0-errata5.2-3/source/openssl_3.0.17-1~deb12u3.dsc @@ -1,3 +1,8 @@ +3.0.17-1~deb12u3 [Fri, 26 Sep 2025 20:59:22 +0200] Sebastian Andrzej Siewior <sebastian@breakpoint.cc>: + + * CVE-2025-9230 (Out-of-bounds read & write in RFC 3211 KEK Unwrap) + * CVE-2025-9232 (Out-of-bounds read in HTTP client no_proxy handling) + 3.0.17-1~deb12u2 [Tue, 05 Aug 2025 09:09:41 +0200] Sebastian Andrzej Siewior <sebastian@breakpoint.cc>: * Revert the following upstream changes to avoid crashes in downstream <http://piuparts.knut.univention.de/5.2-3/#3144617697319740773>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-3] 3f315b761c Bug #58688: openssl 3.0.17-1~deb12u3 doc/errata/staging/openssl.yaml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x249>