-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 15 May 2026 13:57:52 +0200 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx30 libgnutlsxx30-dbgsym Architecture: mips64el Version: 3.7.9-2+deb12u7 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx30 - GNU TLS library - C++ runtime library Closes: 1135319 Changes: gnutls28 (3.7.9-2+deb12u7) bookworm-security; urgency=high . * Cherry-pick fixes from 3.8.13 release for oldstable. + This includes fixes for these issues: CVE-2026-3833 CVE-2026-5260 CVE-2026-5419 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015. + CVE-2026-3832 only applied to release 3.8.9 and later, no patch needed. + Patchset pulled from CentOS c8s (3.6.16), split into patchlets, unfuzzed, adapted for 3.7 (adds 72_0015_gnutls-3.6.16-1810-ocsp-truncated-eku.10.patch). Also added those patches from CentOS c9s (3.8.10) that are relevant for 3.7.9 (but where not for 3.6.16). Closes: #1135319 Checksums-Sha1: 175729cf8814466d427ca2df6d7b9dbbb7609504 871964 gnutls-bin-dbgsym_3.7.9-2+deb12u7_mips64el.deb b42209c7eb6c5658c84b76d96abae0da334c1c2b 620896 gnutls-bin_3.7.9-2+deb12u7_mips64el.deb f3800540f5e9f41c9b183620d2efae888af12d4b 11359 gnutls28_3.7.9-2+deb12u7_mips64el-buildd.buildinfo c4e9e58fd2448fddff91d9df3b1064e63a42be72 273956 guile-gnutls-dbgsym_3.7.9-2+deb12u7_mips64el.deb 2de59089c63660adcb032086b82f4f811dfd1144 451792 guile-gnutls_3.7.9-2+deb12u7_mips64el.deb 12e7944db02073a7e65404205770250d5804edd0 95216 libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_mips64el.deb 9249db3a61afc7f7f64752a80301bb6eda980d53 404772 libgnutls-dane0_3.7.9-2+deb12u7_mips64el.deb f0d870fbdbae65e1dc93328b763753a573d5f2b6 96388 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_mips64el.deb db428e15cc6563a965bd11a00192ce20a938d794 404408 libgnutls-openssl27_3.7.9-2+deb12u7_mips64el.deb a67b88bb4650282811a4f6043a5c90049e36ddc3 1361796 libgnutls28-dev_3.7.9-2+deb12u7_mips64el.deb 15ab7bbb4054bfe327ba5591af5ede4c2829320b 2061580 libgnutls30-dbgsym_3.7.9-2+deb12u7_mips64el.deb 01f65a08998380f58c9488627caa001980005340 1233008 libgnutls30_3.7.9-2+deb12u7_mips64el.deb 15dd9c357b8d2b9ac536268bb6c3562fdf81b5f7 49116 libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_mips64el.deb ddad7795597ee30b59a2e7af0d5f6611953d9cb9 13172 libgnutlsxx30_3.7.9-2+deb12u7_mips64el.deb Checksums-Sha256: 1969e29211333f8c7f4c5b47ca80bdb63bd66f0d4d491a3c5ba66d64c50167e2 871964 gnutls-bin-dbgsym_3.7.9-2+deb12u7_mips64el.deb a5b1e8a95b50498f91243fc3fadaec96a66361337991ebcc5346fbeed585e71c 620896 gnutls-bin_3.7.9-2+deb12u7_mips64el.deb 845c1f3ed6694ac886798fe9c627b0ed95b2e789c79a28f6ef0dda58b8859eea 11359 gnutls28_3.7.9-2+deb12u7_mips64el-buildd.buildinfo 1d44d712a4e5d373f6b6e7565fb631e499090fdde381f9354f94adbad0bfe853 273956 guile-gnutls-dbgsym_3.7.9-2+deb12u7_mips64el.deb 53477f235cc1b54b1899f86ec3ea7e1e622234e5b32abdd2bf53ef08e9b8d667 451792 guile-gnutls_3.7.9-2+deb12u7_mips64el.deb 209dc00595557cf4b426455f10fac5679a10a173bfb3f41c229bff99c7160625 95216 libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_mips64el.deb bb9b1ee98e015fbe19a34ff4903f8f5b6a15358843d655503b42696ace23ac8f 404772 libgnutls-dane0_3.7.9-2+deb12u7_mips64el.deb c4741da34f8cfdfa4c987c9182e13f9ac0e7f09dda0466179331c037c58419cf 96388 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_mips64el.deb c6ba85446569f1860609ff6e80c13744264f308ccdf300bf4ad2e50965dc7fa5 404408 libgnutls-openssl27_3.7.9-2+deb12u7_mips64el.deb dacbd9446553e19b497074dd301ca2b7c33374b7ef285928283c7553c43f13c8 1361796 libgnutls28-dev_3.7.9-2+deb12u7_mips64el.deb 412a4e922a067dd7e0ebb14763a64a103ac04820be26b5e426be0a3ac6d75bc9 2061580 libgnutls30-dbgsym_3.7.9-2+deb12u7_mips64el.deb cf615b392450b8a1fe83ab5b18fcbaf91d3025e3d360e767b44bdf6c1985483d 1233008 libgnutls30_3.7.9-2+deb12u7_mips64el.deb df99c9e2a5b605837843b8925f5678f3fb3709ac946d02357ee209fc13bf11dd 49116 libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_mips64el.deb 6bb9d25a00f28324ba548ca6e7f4701ab2563723f935ad1cfd17af852d5f2bb6 13172 libgnutlsxx30_3.7.9-2+deb12u7_mips64el.deb Files: 4842cd97f4a332cb758ee078dd46d504 871964 debug optional gnutls-bin-dbgsym_3.7.9-2+deb12u7_mips64el.deb 464af8ea5095cf0dc450e7b289a668a0 620896 net optional gnutls-bin_3.7.9-2+deb12u7_mips64el.deb 2fbaa06f33efe4b86db3c9ef50b6aea0 11359 libs optional gnutls28_3.7.9-2+deb12u7_mips64el-buildd.buildinfo 5808ee1da085837f5999f526bf82b6b6 273956 debug optional guile-gnutls-dbgsym_3.7.9-2+deb12u7_mips64el.deb c9abd37e86f3b7eff4714c9d59778be1 451792 lisp optional guile-gnutls_3.7.9-2+deb12u7_mips64el.deb 2cd5818d23e0062b8dd268d968263235 95216 debug optional libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_mips64el.deb f556e37d3c651a846fdade52ebec60ee 404772 libs optional libgnutls-dane0_3.7.9-2+deb12u7_mips64el.deb 570f58b8b04e798f40c9bb939c4421d8 96388 debug optional libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_mips64el.deb 848ff66afe5e77e56515bca16e9fa5dc 404408 libs optional libgnutls-openssl27_3.7.9-2+deb12u7_mips64el.deb 12a9e1643dc4d62b2ec38829282ef237 1361796 libdevel optional libgnutls28-dev_3.7.9-2+deb12u7_mips64el.deb 5b5ed20b23e5e4c6449ae7b6c3d27466 2061580 debug optional libgnutls30-dbgsym_3.7.9-2+deb12u7_mips64el.deb 871b3d060697719973a841f66cc438a3 1233008 libs optional libgnutls30_3.7.9-2+deb12u7_mips64el.deb d51037e44ab6d1e7397ce6f4619f376d 49116 debug optional libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_mips64el.deb 89dcba112ef5cea430b07c6effe1e158 13172 libs optional libgnutlsxx30_3.7.9-2+deb12u7_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7sd7jtCtE5bBJ1Hx/qmHKZssfSAFAmoKKowACgkQ/qmHKZss fSCwag//TDhN4iGVKOWjnXapfzGQ8Crlxy9DRMc8ia0ZQNnlH52hzmDFjOC820oC PlvJ4DqjAOUX8wH2sdXWanvobeVM+6ZkeYJFYkrME627wUvOMzwIxLKUWhZnxCCF feY05T+uLjvhPMLjBi6ktAWiyXksN9YoKVQfqMATSkP18LdO/2WKyNw30aHm8YmH sjnTm6hgs/Ez2zV0g0q62pIqfl/38YZh/QljitmcWxhw5xoJPvwV8vbm4Tui48cE Bc8vsdba8i2zSbtLW43cyz2F8t+PXaZe8koJNh1wbitwuuRlCdPuT7dByVRVyvXC mmDvVldPSHZyNXh6ww/ZFi7IyxhXcpaOErc3Dkp10SJLuIZn8bwSVKQZcoMokLo7 AZ+CylFr3W0AV9tPk5vJKj1gQduhS+WblV2t5xOlaXaE+QOjO4Jhusj3IS1nVSpl J1XLjjBshdaYm7Sb4axy4bmXbeYzOUXKMv+avnJ9CM1/Mzkr7qhCl2s/oRZ1xFtZ S8jghTZmESOEppRKs/JLfbrogYKY1XRSVLjx3LcKCOJIfRKntpa11TDZmhp0EQi5 mb+tDw/CqTSHLx6gy3urJxRzPsbo0BLHn2gyJ0EopcVJPAWqzbecX+u92GBJOqjd ovlaR/5SfzIu0uijSHEaTQox0a7eIm/0etjxuc6gxSLKdMmcoTY= =nZRH -----END PGP SIGNATURE-----