-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 15 May 2026 13:57:52 +0200 Source: gnutls28 Binary: gnutls-doc Architecture: all Version: 3.7.9-2+deb12u7 Distribution: bookworm-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Andreas Metzler Description: gnutls-doc - GNU TLS library - documentation and examples Closes: 1135319 Changes: gnutls28 (3.7.9-2+deb12u7) bookworm-security; urgency=high . * Cherry-pick fixes from 3.8.13 release for oldstable. + This includes fixes for these issues: CVE-2026-3833 CVE-2026-5260 CVE-2026-5419 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015. + CVE-2026-3832 only applied to release 3.8.9 and later, no patch needed. + Patchset pulled from CentOS c8s (3.6.16), split into patchlets, unfuzzed, adapted for 3.7 (adds 72_0015_gnutls-3.6.16-1810-ocsp-truncated-eku.10.patch). Also added those patches from CentOS c9s (3.8.10) that are relevant for 3.7.9 (but where not for 3.6.16). Closes: #1135319 Checksums-Sha1: e44f213080c0ae0134e6bfcb367dc939ec516ceb 4843688 gnutls-doc_3.7.9-2+deb12u7_all.deb aae4e54f61d68c18af63b97552779ce13118adfa 9851 gnutls28_3.7.9-2+deb12u7_all-buildd.buildinfo Checksums-Sha256: b8d23e45a2fdded941d823d7bd328f3349a9b01cc9519ab6c9ed63a352751803 4843688 gnutls-doc_3.7.9-2+deb12u7_all.deb 44e2796b28a810a889ca8643ccef83837e25bf7d1d9111c09cc5cb0e8f16f268 9851 gnutls28_3.7.9-2+deb12u7_all-buildd.buildinfo Files: 64e5855c933d934aba74050767130c2a 4843688 doc optional gnutls-doc_3.7.9-2+deb12u7_all.deb 0697b559911aa04789336aa45ab9c531 9851 libs optional gnutls28_3.7.9-2+deb12u7_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmoJ+BEACgkQmgPNRvTf /zeDBw/+O0+wf/IklNga7ow2ZgcG6j22fKUazb8KAHxCpJMeaJRfKf3eEqWB2b+n aX2Ow5JmJkbvdV7bWyVG5x9/tZ5FGlvENdh3u0Ne9tRzS8oE5vf7V/iVTXAmNpxp bDD3V84ZKifDnJOmwj+HkM6gFqa+Z+jMbrJ9gAC4zW/b8b39nGqnu0tGIhD5W7Q+ em7/ZJeYYY1bLmNbyNIzXBIh9tBi4rh1GUP65mqTmP+Y9YrCB/7iDNWnw47PvHVZ 9Ok74sycZk6OsCxMPAKLgypHliTIsUFgkEYcYTF8WWxtKTCM77EZFcOe5+bWpOp0 nmIPWhygflqXX34ISCHsOesKZZgbWChXT0q8eVh6Y9Fki8K/zkYtyZZlhw5vgg3C aKIJprFfiCDZGCmdwd3oxfJIkyNwB+aupXIMWsQ3LoAM4STBbfrZijE/NSv7axsX M35zhv/Z3Gtb3H4xEUbdFthPCAGOlHl4odxVBtteAGnzkVUbL9GJQvSFMsMGpYFJ fJ+3XItiHL6bXGi+mlbKig+uOjaE9iCGTbHPoImEtnqwQ0w9pHuqEydNhyENE/rn 0TpZM06dOn8kfPTwsa11KlqYHS+bpg8s3hcjfDz43dw2JJgwsEwLVN2bdBG4ZmqA m3EdhjNv1p1faY8wKZ1MvIqNuua24Mp7o1icrGAvAig+PXYXD1w= =vfj4 -----END PGP SIGNATURE-----