Skip to content

feat: update openssl to 3.5.6-1~deb13u2#21

Draft
deepin-community-bot[bot] wants to merge 1 commit into
masterfrom
dcbot/debian/3.5.6
Draft

feat: update openssl to 3.5.6-1~deb13u2#21
deepin-community-bot[bot] wants to merge 1 commit into
masterfrom
dcbot/debian/3.5.6

Conversation

@deepin-community-bot

Copy link
Copy Markdown
Contributor

This pull request is requested by @UTsweetyfish.

Basic Information

Old Version: 3.2.4-0deepin9
New Version: 3.5.6-1~deb13u2
Old version may contain dde / deepin patches. Please review more precisely.

Potential transition

  • libssl3 is not present in the new package.

64-bit time_t transition

Caution

DCBot assumes this package is already gone through 64-bit time_t transition.

Patch series

--- a/debian/patches/series
+++ b/debian/patches/series
@@ -4,53 +4,24 @@
 pic.patch
 c_rehash-compat.patch
 Configure-allow-to-enable-ktls-if-target-does-not-start-w.patch
-Remove-the-provider-section.patch
 conf-Serialize-allocation-free-of-ssl_names.patch
-Always-call-OPENSSL_cleanup-prior-to-exit.patch
-Add-support-for-Zhaoxin-SM2-3-4-instruction.patch
-deepin-sw64-support.patch
-1000-Support-TLCP-and-GM-T-0024-2014.patch
-bugfix-ZHAOXIN-GM-certificate-verify-error.patch
-kek_unwrap_key-Fix-incorrect-check-of-unwrapped-key-size.patch
-SM2-Use-constant-time-modular-inversion.patch
-use_proxy-Add-missing-terminating-NUL-byte.patch
-Correct-handling-of-AEAD-encrypted-CMS-with-inadmissibly-.patch
-Some-comments-to-clarify-functions-usage.patch
-Test-for-handling-of-AEAD-encrypted-CMS-with-inadmissibly.patch
-ossl_quic_get_cipher_by_char-Add-a-NULL-guard-before-dere.patch
-Check-the-received-uncompressed-certificate-length-to-pre.patch
-Fix-heap-buffer-overflow-in-BIO_f_linebuffer.patch
-Fix-OCB-AES-NI-HW-stream-path-unauthenticated-unencrypted.patch
-Check-return-code-of-UTF8_putc.patch
-Verify-ASN1-object-s-types-before-attempting-to-access-th.patch
-PKCS12_item_decrypt_d2i_ex-Check-oct-argument-for-NULL.patch
-Ensure-ASN1-types-are-checked-before-use.patch
-dane_match_cert-should-X509_free-on-mcert-instead-of-OPEN.patch
-Fix-NULL-deref-in-ec-dh_cms_set_shared_info.patch
-Test-for-DH-ECDH-CMS-KARI-processing-NULL-pointer-derefer.patch
-Fix-NULL-deref-in-rsa_cms_decrypt.patch
-Add-test-for-CMS-decryption-with-RSA-keys.patch
-Fix-NULL-Dereference-When-Delta-CRL-Lacks-CRL-Number-Exte.patch
-Added-test-for-CVE-2026-28388.patch
-Avoid-possible-buffer-overflow-in-buf2hex-conversion.patch
-rsa_kem-validate-RSA_public_encrypt-result-in-RSASVE.patch
-rsa_kem-test-RSA_public_encrypt-result-in-RSASVE.patch
-CVE-2026-34180.patch
-CVE-2026-7383.patch
-CVE-2026-9076.patch
-CVE-2026-34182-fix.patch
-CVE-2026-45445.patch
-CVE-2026-45447.patch
-CVE-2026-34182-test.patch
-
-# CVE-2026-45446 - Incorrect tag processing for empty messages in AES-GCM-SIV and AES-SIV
-CVE-2026-45446.patch
-
-# CVE-2026-42766 - NULL dereference in password-based CMS decryption
-CVE-2026-42766.patch
-
-# CVE-2026-42767 - NULL pointer dereference in CRMF EncryptedValue decryption
-CVE-2026-42767.patch
-
-# CVE-2026-42770 - FFC-DH peer validation uses attacker-supplied q
-CVE-2026-42770.patch
+Reject-oversized-inputs-in-ASN1_mbstring_ncopy.patch
+cms-kek_unwrap_key-Fix-out-of-bounds-read-in-check-byte-v.patch
+cms-kek_unwrap_key-test-for-fix-out-of-bounds-read-in-che.patch
+Avoid-length-truncation-in-ASN1_STRING_set.patch
+pkcs12-verify-that-the-pbmac1-key-length-is-safe.patch
+Reject-potentially-forged-encrypted-CMS-AuthEnvelopedData.patch
+Add-tests-for-CVE-2026-34182.patch
+QUIC-stack-must-limit-the-number-of-PATH_CHALLENGE-frames.patch
+Add-test-for-path-challenge-flood-mitigation.patch
+Fix-NULL-dereference-in-QUIC-address-validation.patch
+Fix-potential-NULL-dereference-processing-CMS-PasswordRec.patch
+Test-for-CVE-2026-42766.patch
+Fix-potential-NULL-dereference-in-OSSL_CRMF_ENCRYPTEDVALU.patch
+Enforce-implicit-rejection-for-CMS-PKCS-7-decryption.patch
+Use-the-correct-issuer-when-validating-rootCAKeyUpdate.patch
+Match-the-local-q-DHX-parameter-against-the-peer-s-q.patch
+Apply-the-buffered-IV-on-the-AES-OCB-EVP_Cipher-path.patch
+Fix-handling-of-empty-ciphertext-messages-in-AES-GCM-SIV-.patch
+Fix-possible-use-after-free-in-OpenSSL-PKCS7_verify.patch
+Test-for-CVE-2026-45447-UAF-in-PKCS7_verify.patch

@deepin-ci-robot

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

TAG Bot

TAG: 3.5.6-1_deb13u2
EXISTED: no
DISTRIBUTION: trixie-security

@deepin-ci-robot
deepin-ci-robot requested a review from BLumia July 6, 2026 06:58
@deepin-ci-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign liujianqiang-niu for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant