-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 14 Feb 2026 15:49:14 +0100 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx30 libgnutlsxx30-dbgsym Architecture: i386 Version: 3.7.9-2+deb12u6 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx30 - GNU TLS library - C++ runtime library Closes: 1121146 Changes: gnutls28 (3.7.9-2+deb12u6) bookworm-security; urgency=high . * Add patch for CVE-2025-9820 / GNUTLS-SA-2025-11-18 from 3.8.11. Closes: #1121146 * libgnutls: Fix name constraint processing performance issue Verifying certificates with pathological amounts of name constraints could lead to a denial of service attack via resource exhaustion. Reworked processing algorithms exhibit better performance characteristics. Reported by Tim Scheckenbach. [Fixes: GNUTLS-SA-2026-02-09-2, CVSS: medium] [CVE-2025-14831] Checksums-Sha1: 894931dba2d53fa3d03b013a3e2ba503f10c6639 797920 gnutls-bin-dbgsym_3.7.9-2+deb12u6_i386.deb fd4cad735eab8d90b999d3cda415b0e409de725e 646660 gnutls-bin_3.7.9-2+deb12u6_i386.deb 300845fa4a0acfba1849771d5a09604b477117ad 11347 gnutls28_3.7.9-2+deb12u6_i386-buildd.buildinfo 59c5d8edb394af3f171fcc042f3a01e136aa2eff 242048 guile-gnutls-dbgsym_3.7.9-2+deb12u6_i386.deb 21d665f8b166214b06e9fd84c779916598dc0989 463828 guile-gnutls_3.7.9-2+deb12u6_i386.deb 8cf0a276075f40299c90e9967e6b340ab416f3e8 83940 libgnutls-dane0-dbgsym_3.7.9-2+deb12u6_i386.deb 79494cc01c46fb578acc5a33bd8cde0ce7983315 407224 libgnutls-dane0_3.7.9-2+deb12u6_i386.deb e7fee42b37635fa311430456b0f598ce76245629 84012 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u6_i386.deb f9f36673077349bb3bef2d12f5d80f2efd40759a 407420 libgnutls-openssl27_3.7.9-2+deb12u6_i386.deb 4c368ac7cdef0b2891d838cfc6d8aaf439510256 1421696 libgnutls28-dev_3.7.9-2+deb12u6_i386.deb b7d0944366c14d73d08443e8190f2a4fcc1caf46 1741328 libgnutls30-dbgsym_3.7.9-2+deb12u6_i386.deb 6ba514ce6f8cace7a211f4197e8025d2b149b552 1407740 libgnutls30_3.7.9-2+deb12u6_i386.deb 709fd17c246d0f152d4a1613bcf1ac1004ad0e6a 45452 libgnutlsxx30-dbgsym_3.7.9-2+deb12u6_i386.deb 325e7a7d8ab99d6fcc48fd3ae8dbcaab281e66d5 15424 libgnutlsxx30_3.7.9-2+deb12u6_i386.deb Checksums-Sha256: 78593dab1cbfe16d7aac5f1d571408d713b6aa6ded1c5f39387bc166070f7cf3 797920 gnutls-bin-dbgsym_3.7.9-2+deb12u6_i386.deb 1a2783beb285314f12d655b97e693eed430d5118d59059a989c536e06c0de2c4 646660 gnutls-bin_3.7.9-2+deb12u6_i386.deb 1e07604577a8950a7c2aa45c1ffce0b7e00ebb3177e217dc1b86dd418f1e16ea 11347 gnutls28_3.7.9-2+deb12u6_i386-buildd.buildinfo d0c996a6a0edf84ecb09fee6b158d49cf0f41a79ec59e2ac0556adf89e7129c0 242048 guile-gnutls-dbgsym_3.7.9-2+deb12u6_i386.deb deedbe76bc72562138dbebe2ccef88b1a9db918ea0e7068e2e5f8fb838fd3cc7 463828 guile-gnutls_3.7.9-2+deb12u6_i386.deb 83e6382e9caa26d2e5269d1c0996fbfcaf2b603f95dc2cabf731d841177483af 83940 libgnutls-dane0-dbgsym_3.7.9-2+deb12u6_i386.deb de59dd000b9f304986bb84d9584861ea7c42b32208865f425fc4bbd543bdbc2e 407224 libgnutls-dane0_3.7.9-2+deb12u6_i386.deb 0013509c445311fc69a12758312f7df183e907191b336b764f0991dfc8a5745c 84012 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u6_i386.deb 5ce25d6dfd42a5cb8de941f98d95f79934c21d67cd2e1e73cd4ac2bc3e711bac 407420 libgnutls-openssl27_3.7.9-2+deb12u6_i386.deb 2132c4ce10d75a84ab4f30a105b0c916c450c6930466df7ef51f633cfaf4e25a 1421696 libgnutls28-dev_3.7.9-2+deb12u6_i386.deb 8dd7ef9c561da4116ed42619eb78f6daf636268b604dc4be9e573f9a80a719db 1741328 libgnutls30-dbgsym_3.7.9-2+deb12u6_i386.deb 4990dbfafd59400f89d3ac834f98b6b1812401af047e3b5df6893ca5fca762a7 1407740 libgnutls30_3.7.9-2+deb12u6_i386.deb 88b11d6a705f7bc43166878bf1975081fdfa539a54a7406387834de306eb0d60 45452 libgnutlsxx30-dbgsym_3.7.9-2+deb12u6_i386.deb 6e3062084cf48727b18fbdaaa0d7cf599b461fbf333c50ce2b0edddefe02fd0b 15424 libgnutlsxx30_3.7.9-2+deb12u6_i386.deb Files: 0c6ea2500b7a5b0a348501037e76f81d 797920 debug optional gnutls-bin-dbgsym_3.7.9-2+deb12u6_i386.deb 73c4643d568de635a0374fb7f9682ce7 646660 net optional gnutls-bin_3.7.9-2+deb12u6_i386.deb 67747bf69fb349ccdc2020fde4f2a729 11347 libs optional gnutls28_3.7.9-2+deb12u6_i386-buildd.buildinfo 8613a2ba708776ec9fe0c9642481f14f 242048 debug optional guile-gnutls-dbgsym_3.7.9-2+deb12u6_i386.deb 0936e477975a77da24ee6f932849399b 463828 lisp optional guile-gnutls_3.7.9-2+deb12u6_i386.deb ca235eaa5aaf76c9ac8327a85c5ed96c 83940 debug optional libgnutls-dane0-dbgsym_3.7.9-2+deb12u6_i386.deb 4b96a0844b2f0df9a26ce1f8049055aa 407224 libs optional libgnutls-dane0_3.7.9-2+deb12u6_i386.deb 77661c6aa92ae2627ac241f9306f9019 84012 debug optional libgnutls-openssl27-dbgsym_3.7.9-2+deb12u6_i386.deb f20b5bb5edd272e00a4be89d25e9f64f 407420 libs optional libgnutls-openssl27_3.7.9-2+deb12u6_i386.deb a11f375d91d0b1708269c0249678861c 1421696 libdevel optional libgnutls28-dev_3.7.9-2+deb12u6_i386.deb 1c5decf7f2819bdcbb7edc62d49f6de8 1741328 debug optional libgnutls30-dbgsym_3.7.9-2+deb12u6_i386.deb d1935c813f22ee80d7e8ffdaaaa7681f 1407740 libs optional libgnutls30_3.7.9-2+deb12u6_i386.deb e8dbc207fa108224897e6928f811de58 45452 debug optional libgnutlsxx30-dbgsym_3.7.9-2+deb12u6_i386.deb 10a783b159d3c83532b516fda3154954 15424 libs optional libgnutlsxx30_3.7.9-2+deb12u6_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErwLLVsiCiGZggzpHJuP6X4A0XeIFAmmSBxwACgkQJuP6X4A0 XeL0rQ//TZto6DE/jDRRqBzAMaP/QmXADnW5SBsdjklvEPCGE0pKQvDZgL7Z/IZy DQnYAKwSX+i5OxX134e/vErUKnCwxhF5VM+ipTrVpK804wgFdQT6Et/U3CBqiCqY 7oRG+gqbWx62VqdXvlRm7ORe45COYh8IOZOKhJOD5foyvZxTIDGT7FZSZrZybcNl fRBJBTjWK56hQUtpJ0U/nE7KF22Xksaho2psZhl0swu1/IbiqjpfQGBQm4IZrNqW oI4kisB2pzbFP9P1HprwXnOWJmUGfLROZFc2vpajzKdex+KgTBIwb80aRaJqsptt trpGDsgOmxAEsCa/NDJ/cUpThZBG/2ekKmpnk4HKbBs+ElF+oIXpf1wniwBwa8dQ Iy5OSTgr9NaPw2A5q9kzxZYfh+/S26zuu70Mz/I4ebCiTe3sbhCQZQgCaSIvaRTv GSMQCpoiS7FXGWXQU9hkzkJ0qQIhMgBGei34ekiWNIZ8QCD8WIV+bje2zZ8gqUiY vtv6W1gtYDnUy9UG9HNJLpAiVt2+ygdhnVpVK58sM43jAd8LM3HVmZYJrbw8pGEo AkfUzQaideDwNPHUY0dPjTF9tz7R4FwA4hR/e3Po9NYkmREIlH2pUYtV0NU4ujWN Yk8pXuNajDAQlvHK7CX9io2Z8Mhj86mP0kXiugJ6h+gI8qclq8Q= =SAsH -----END PGP SIGNATURE-----