-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 21 Nov 2025 00:45:17 +0100 Source: openvpn Binary: openvpn openvpn-dbgsym Architecture: armel Version: 2.6.14-1+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Bernhard Schmidt Description: openvpn - virtual private network daemon Closes: 1114249 1121086 Changes: openvpn (2.6.14-1+deb13u1) trixie-security; urgency=medium . * Cherry-pick patches for CVE-2025-13086 - check-message-id.patch: Check message id/acked ids too when doing sessionid cookie checks - bugfix for floating client problem, code prequesite for the CVE patch to apply - CVE-2025-13086.patch: Fix memcmp check for the hmac verification in the 3way handshake being inverted (Closes: #1121086) * fix-ftbfs-kernel-6.16.patch: Fix compilation against 6.16+ kernel headers (Closes: #1114249) * d/gbp.conf: set debian-branch for trixie Checksums-Sha1: 7ad80274d5bfac63ea52e66710483fc2f7bd7cbf 1251988 openvpn-dbgsym_2.6.14-1+deb13u1_armel.deb 5cd7cc98422064ab6b60c346e6e438b56eff21f9 6957 openvpn_2.6.14-1+deb13u1_armel-buildd.buildinfo 6d279e5c772050f7d41b20ee1552110ba5c37193 610356 openvpn_2.6.14-1+deb13u1_armel.deb Checksums-Sha256: e1a6cca613966aad3e4fbb55066b11b8bd567fb7e1ea2813f640dd25b680fc48 1251988 openvpn-dbgsym_2.6.14-1+deb13u1_armel.deb 0e63d1fee9c4ce673afe9829f6fd30028d704628f8139131181fa0739d1cd44e 6957 openvpn_2.6.14-1+deb13u1_armel-buildd.buildinfo 0bc630a714c00f4b6a79ac66537bfbcd7b0a915558c781d6bcd32b1f903327cd 610356 openvpn_2.6.14-1+deb13u1_armel.deb Files: 153cb51416e135f7a076ec04c0ee12f8 1251988 debug optional openvpn-dbgsym_2.6.14-1+deb13u1_armel.deb de20e40dcf8c712a3a48fc37b560dd98 6957 net optional openvpn_2.6.14-1+deb13u1_armel-buildd.buildinfo f0b77624e4b38759449d78c6c80d9e22 610356 net optional openvpn_2.6.14-1+deb13u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmksyFUACgkQOQKMdMnE H5MkpBAAm9CLsAGSGHL9hA3FruoC+RgPkBMV6uuhIdYndqYbGOb7RhB5z+CSvk8r R+HupbAf2kTt1gQEzaPgaQveF2ldqoY8yukV9pkSbdV01a6EQRGBaOHiUR0YyFFj 6JouBZkDUoDpCxBB5STYc1Cl6K/DJZ+bUl6XfICk2I06PAG0qvXazp/7a1vmkCZv wPh1JAASbbLzOBmmnsKUunigWC8U5uNVAmblB28qmU9y75WlDGLYR0n0dJkM0ULy lV5JCNGSxjUPU3p1ZYkX/9yMaeAchxI4nsfMzMGayEkS8P2CT2W62npuUbQClChF +d7Fjh+mmpO2gsRVXCbXfBSIx/5FEWsvNWj3pgCbWzgko5geWVWcoyyxB9ybxHda j4PiPDymF0ieW8rQhdb+xu9K7WdjaORPTLcL35scKBj4i9eaX7KGlJYy94lX4H+O LJoWJwRLZA5mOZTi3JNIEW6BGpTXQJB7Okuk0smsD3pyycdbDpkTAcJmWbdRT53u CQWIO/Ja8FaTYaJqFSsoKbPBRqgB4jraI6Mwbc7B97CylavZYv2xQVsz/J6uesKU PGFGGe/zngCfSunf/F4dk9/cAMqwYH5KXPYrl6iXZsZgC26FsnGCY0RAi0jlpVJ4 Rc5jSJNtGki4vL5uFUqkFB6pqdojmJ8KSPbyka1JnpIYbjvjnAI= =ljB5 -----END PGP SIGNATURE-----