-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 02 Apr 2025 17:45:15 +0200 Source: openvpn Binary: openvpn openvpn-dbgsym Architecture: s390x Version: 2.6.3-1+deb12u3 Distribution: bookworm Urgency: medium Maintainer: s390x Build Daemon (zani) Changed-By: Bernhard Schmidt Description: openvpn - virtual private network daemon Closes: 1074488 1086653 1101935 Changes: openvpn (2.6.3-1+deb12u3) bookworm; urgency=medium . [ Bernhard Schmidt ] * Cherry-Pick upstream fixes for various CVEs (Closes: #1074488) - CVE-2025-2704: possible ASSERT() on OpenVPN servers using --tls-crypt-v2 (Closes: #1101935) - CVE-2024-5594: malicious peer can DoS or send garbage to logs - CVE-2024-28882: client can circumvent management client-kill both (Closes: #1074488) * Run salsa pipeline in Bookworm environment - add d/source/options to make it build in Bookworm Salsa . [ Aquila Macedo ] * d/p/sample-keys-renew-10-years: import upstream patch to update expired certificates used in the build-time tests (Closes: #1086653) Checksums-Sha1: 75b16db8a233acfaa32070e7d4d956398dc453de 1233604 openvpn-dbgsym_2.6.3-1+deb12u3_s390x.deb 5699d6a5f78208fe59d0de58418fec68e0be65a3 7582 openvpn_2.6.3-1+deb12u3_s390x-buildd.buildinfo babbafeab1af9e0b6564f2902ff5bef5f406e698 604388 openvpn_2.6.3-1+deb12u3_s390x.deb Checksums-Sha256: 1516ea9c5a9db7488bb784994d980f8645d1b585bfd37737947c887323e5d305 1233604 openvpn-dbgsym_2.6.3-1+deb12u3_s390x.deb 43de0b90cde52ddfdbfcb90093aa5fe7270b7a32b9e025dbe048a78601354c06 7582 openvpn_2.6.3-1+deb12u3_s390x-buildd.buildinfo 9d44bee9f9102ea0593e8c06ca9ddd9ff239d0e47a9e697262dddd003d7bf517 604388 openvpn_2.6.3-1+deb12u3_s390x.deb Files: 71aa365581af9c20b11b8f141958285b 1233604 debug optional openvpn-dbgsym_2.6.3-1+deb12u3_s390x.deb 76c391993ffd44164763c01329613c2b 7582 net optional openvpn_2.6.3-1+deb12u3_s390x-buildd.buildinfo f50cee2494017c4b50703771426efbd1 604388 net optional openvpn_2.6.3-1+deb12u3_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZTC4/c20pi1/n7UBUhVQ83ojQ7QFAmgeMSoACgkQUhVQ83oj Q7SSnBAApa7n6yKVtIV59bveoUUXjSxarGtPjf09BMk65w70fvHOLafB05jSrEZN sC2yn3jGYmO9PsgHypw5wHZjIAfGQtBNrFd16YuSb4Z3a66z1NpJGyftvUDy2gUr +ioE3VDrL3gfENJvsSReOTGBttkodeyfOWUsTosceMsCF4tcTGrXW/UTMa1Dlf8N 7y6zmgGp6BPW1Mk9ZfA3NGGf7wli8ibijZ3Pi2ck0n035v5oixbqxjITwVrTaO+Y w/CQ2hOeTGn1fIHkISdRtUe8J6d9QKVO9rAq0DoQJPF0t9ztJo5xGFPElMNKzY6x 7rea9w/uLeDxMiukNlGhpIxqqLvPNPz0NTyy2W1w0Vk4mf++DuG+wPKy1OQzNbxG 296jD7xaN2PW7xOkrSqbhDDE2f4FwiwDV39Gc7jsEJlIpnO7bDf4Zduwxoy2geHD Io3bI6koDzBUE0bKrYk2Wx9gjNHzHd9n46wO8UK4mzM54teTm9PcxW3ydMSO1hNm DyrsZrYk55N5Jyxa5k76x3v0O+mVLKYhKXYeeFD/FuhS3O3ddD4KdEspZFr3Uq+Y zqR1liZ+IvRO1r/BR5IM45OnSdSARsz0SXqtTMUlnQXH/SUOaZdnoPlVLeTaFU6U AIfQfQS+GSZ8qUMJRzX+3I7RC6wREocwHxM97hWjk6eW6cMB/Xw= =OKNx -----END PGP SIGNATURE-----