-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Sep 2025 20:59:22 +0200 Source: openssl Binary: libcrypto3-udeb libssl-dev libssl3 libssl3-dbgsym libssl3-udeb openssl openssl-dbgsym Architecture: amd64 Version: 3.0.17-1~deb12u3 Distribution: bookworm-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Sebastian Andrzej Siewior Description: libcrypto3-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl3 - Secure Sockets Layer toolkit - shared libraries libssl3-udeb - ssl shared library - udeb (udeb) openssl - Secure Sockets Layer toolkit - cryptographic utility Changes: openssl (3.0.17-1~deb12u3) bookworm-security; urgency=medium . * CVE-2025-9230 (Out-of-bounds read & write in RFC 3211 KEK Unwrap) * CVE-2025-9232 (Out-of-bounds read in HTTP client no_proxy handling) Checksums-Sha1: 9246948bb1661bb856c22632c5fb59600757a8c3 1526880 libcrypto3-udeb_3.0.17-1~deb12u3_amd64.udeb 2cf388fa75d8876989856622d8977590176a275b 2440816 libssl-dev_3.0.17-1~deb12u3_amd64.deb 2b80dcc010532e0efb7b26a96c7a673f925a1d0f 4781904 libssl3-dbgsym_3.0.17-1~deb12u3_amd64.deb e99278e19558c786762fcda3b054cae1862deaca 221260 libssl3-udeb_3.0.17-1~deb12u3_amd64.udeb e89b79a9c049da5bca4d87b510e194a0121dfc82 2028292 libssl3_3.0.17-1~deb12u3_amd64.deb 119bfe78ed4cb1a3ee2c9abf5ac9fa1b9465cf5e 690004 openssl-dbgsym_3.0.17-1~deb12u3_amd64.deb 0d474fd378e46336ce56085c970705f8db2cb99f 7817 openssl_3.0.17-1~deb12u3_amd64-buildd.buildinfo 4ae1a3e3f3de54fcb2ba52dfc6fc4e95c9dc41cc 1434432 openssl_3.0.17-1~deb12u3_amd64.deb Checksums-Sha256: 55a6d0ad2110179742faef1c09d32d144c4289e1b3a6351693e064be4f1ed7bb 1526880 libcrypto3-udeb_3.0.17-1~deb12u3_amd64.udeb b4a236c13a5b905fdd272c8a122b7644dfb881c1bfb8a4291e32f48ead551bdf 2440816 libssl-dev_3.0.17-1~deb12u3_amd64.deb 8949da8ca99648c662b2faa88802ab651a375b10c2aeac85953b6eb83c5e0f94 4781904 libssl3-dbgsym_3.0.17-1~deb12u3_amd64.deb d2792ece86b72fb89f2a77e5213c51d7083c86ba0fe721ca2431ae0625237f26 221260 libssl3-udeb_3.0.17-1~deb12u3_amd64.udeb 49a24ea92f19ee029e694107cfcf4f7e6298883a28e23a80ec999a0746d4a869 2028292 libssl3_3.0.17-1~deb12u3_amd64.deb ad5d77427d145641679bb2961f25999b222c9e4d7addbc0ec03de398087a1ab3 690004 openssl-dbgsym_3.0.17-1~deb12u3_amd64.deb b9a853356e07f4544119e90b71ab3b09aa410ba820387fe3423e1d67e390f1a9 7817 openssl_3.0.17-1~deb12u3_amd64-buildd.buildinfo 8d86ffbc3e49b8df1cdf47d0ebe76ce3c806d714724669646d21e222db1d293b 1434432 openssl_3.0.17-1~deb12u3_amd64.deb Files: 1d7a886d6a7a5087d86754797238cc58 1526880 debian-installer optional libcrypto3-udeb_3.0.17-1~deb12u3_amd64.udeb cd9e98871654a9381ec22b14ff9778aa 2440816 libdevel optional libssl-dev_3.0.17-1~deb12u3_amd64.deb 233e254ef1079547ab7a15b64d77dbd0 4781904 debug optional libssl3-dbgsym_3.0.17-1~deb12u3_amd64.deb e9070f47976cece2386aa8d5ec82fca2 221260 debian-installer optional libssl3-udeb_3.0.17-1~deb12u3_amd64.udeb 02242dd178e69bef809771c112b7b9a6 2028292 libs optional libssl3_3.0.17-1~deb12u3_amd64.deb ecb076da51018af4f1602005da839569 690004 debug optional openssl-dbgsym_3.0.17-1~deb12u3_amd64.deb 6766a1635fec697fa8c31fb75e06e86f 7817 utils optional openssl_3.0.17-1~deb12u3_amd64-buildd.buildinfo dad291bf187b2509c93235dbf2d9530e 1434432 utils optional openssl_3.0.17-1~deb12u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEaPzFtKPtF0JrKPV5iZlfn74WV6kFAmjW+lMACgkQiZlfn74W V6nPOQ/+JTyc8j/Yx3YfGUFp5kUOlCJxvJHaStzqZxAr4eW7taIjpJuXv8yAZ84G BFQz7r3IS0EhrrdtkvuZ0OTCd7CMfZ6JPAWR0BSJONNduOAJMpfV+mf4tr7pKusU 3PCx9Fjx5VZgMoDor3ibs1uGoyh8yVTaulRYb4aMq4V1dFNo5y66bDkexNihBKu1 m/j5Hezp6F5jzuGCJCa16A5APrj7PM3eJNY3kNODdU/T9zA3RdIfC3Q+/nTbtctc tkY2pN/sc3nxUXz+AJhymoCQp9XHUxOzIeuDEWcvGJzidF9mxtx2sT5vhzFnzpO2 oKaO8RwQiXArEMPzTa/BI8gVPIVY/5uc2vfJC44cPSKlMYmJLpVX3jLfzhi5PcKk xiHsj7GmhOr+NhicyKlDrd0PRE72EosvH/tCw5Zcknrd6NdYKq6EwVoZcZTqeEzr iu+oX/h5MG+cgY0BuNrcelr2kuZXndoF8FtlM/b3UpQbuHYyESGK58/SMCqvzkov 7xnvxEfeB8MVeaYQ3ceqCQBAngKIvBZFXHw0k2QyR+1bpKCbfG1fqduc3joqDjC9 BluEG1n3xH9VC4GC7dZoJbNUAMw6bxzzYBwpMYl8AUUGqNzHODsXneJiSws76XQv NCeoAp0AyAf3gD/m1Ii8+2VB2AS61CXTR+7WJZJqZNFK9PaVhjA= =j796 -----END PGP SIGNATURE-----