-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 15 May 2026 13:57:52 +0200 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx30 libgnutlsxx30-dbgsym Architecture: mipsel Version: 3.7.9-2+deb12u7 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx30 - GNU TLS library - C++ runtime library Closes: 1135319 Changes: gnutls28 (3.7.9-2+deb12u7) bookworm-security; urgency=high . * Cherry-pick fixes from 3.8.13 release for oldstable. + This includes fixes for these issues: CVE-2026-3833 CVE-2026-5260 CVE-2026-5419 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015. + CVE-2026-3832 only applied to release 3.8.9 and later, no patch needed. + Patchset pulled from CentOS c8s (3.6.16), split into patchlets, unfuzzed, adapted for 3.7 (adds 72_0015_gnutls-3.6.16-1810-ocsp-truncated-eku.10.patch). Also added those patches from CentOS c9s (3.8.10) that are relevant for 3.7.9 (but where not for 3.6.16). Closes: #1135319 Checksums-Sha1: c2dcdd7ad325e96267c3263a0527fc3aee1bc8c2 857412 gnutls-bin-dbgsym_3.7.9-2+deb12u7_mipsel.deb bd77c6fc675eced05db2afaa9ec153fb7f3156ad 624428 gnutls-bin_3.7.9-2+deb12u7_mipsel.deb 85fa61f3d3d0a1076bf03416b6309730aa29d917 11278 gnutls28_3.7.9-2+deb12u7_mipsel-buildd.buildinfo 68bff59573095b94ed24809456194653a786b58f 267384 guile-gnutls-dbgsym_3.7.9-2+deb12u7_mipsel.deb 25a694af57655b726ca60947a7a20ef419f68917 449472 guile-gnutls_3.7.9-2+deb12u7_mipsel.deb c72bf1c29afd94d0bec85f9b88830c30a20036e4 93040 libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_mipsel.deb bc659dc94c43a01e560e9d9477ab1f5bc57dd1fc 403496 libgnutls-dane0_3.7.9-2+deb12u7_mipsel.deb 9a40132877c352e67a69642c22d4b09e63df7eaf 94072 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_mipsel.deb 777cbd27ce242bf474d54722460fa84be17d797f 403208 libgnutls-openssl27_3.7.9-2+deb12u7_mipsel.deb 4e058b0e875aaea828b34fdb2792c01e4e344544 1357148 libgnutls28-dev_3.7.9-2+deb12u7_mipsel.deb 8923e3cc8340bbcc966b05efe66a6a8487d95631 2018484 libgnutls30-dbgsym_3.7.9-2+deb12u7_mipsel.deb b75f236d576aa0da7a98b6cdd39d32c6c7a2d875 1235332 libgnutls30_3.7.9-2+deb12u7_mipsel.deb 270fce3cec2075e488dd8b5601e0e3f0eafcf223 48092 libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_mipsel.deb f038a22b248481490a1833b2fa925c946476a613 12952 libgnutlsxx30_3.7.9-2+deb12u7_mipsel.deb Checksums-Sha256: 6e6a2e825637c006ff62d7da632974b667abd650f2de84169d04e3e25f11bd60 857412 gnutls-bin-dbgsym_3.7.9-2+deb12u7_mipsel.deb 56174ab0867b0d09c48a096ae45b9ec6fa4aa6b69446dcea0a5cff475cb63a25 624428 gnutls-bin_3.7.9-2+deb12u7_mipsel.deb 1df854f2d562f1d8c25aad8dbb95b0b22e2781cf800ef9139caa7b49082b21d0 11278 gnutls28_3.7.9-2+deb12u7_mipsel-buildd.buildinfo 2875858ce7899efb5f0d6b09a8695af3f4e2102264729343ba88dddc0a381c0f 267384 guile-gnutls-dbgsym_3.7.9-2+deb12u7_mipsel.deb 63749a7bbd6a290fe0590a84af2a870003358ab776c79b3343db45730a66f536 449472 guile-gnutls_3.7.9-2+deb12u7_mipsel.deb ce396addf4d097508b22a86c89057401ead3b86f8e5f0177a4ccfca6467d5fa9 93040 libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_mipsel.deb 917aa36e073e916d1c13b219300293d70339325e43b01e8a1d3123aa3573f2c2 403496 libgnutls-dane0_3.7.9-2+deb12u7_mipsel.deb 3513c733a0d846748d9b29228746314ca4eaff3b77d98d7d69bfd8cd7e623516 94072 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_mipsel.deb afa7e4104e8d4a59e3fd7a1870de2d9bb6c0bc36aee98eaefc9d691e6585c3aa 403208 libgnutls-openssl27_3.7.9-2+deb12u7_mipsel.deb f04fc3c91f9a4648a5f05aa7013bdc29bc1a96045cb73cecaa37fee59cbd5888 1357148 libgnutls28-dev_3.7.9-2+deb12u7_mipsel.deb 8d6cc4e826168d7c535bd460a6c9eb3f5d14b932252fb390ada145acaf90c16c 2018484 libgnutls30-dbgsym_3.7.9-2+deb12u7_mipsel.deb 107c70adc0c23aaa5e8ef960234ffb9dfeee4d61d369c22def87bd2fe8f9aae1 1235332 libgnutls30_3.7.9-2+deb12u7_mipsel.deb 065cd7faf0f98cf0e13510d40252d9359ff8dd11e48db2557c3a9616f49de822 48092 libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_mipsel.deb cc826db7f438db6ce84bfb7fb5e113dcefdf337b683a85f8e83229004c60ab5a 12952 libgnutlsxx30_3.7.9-2+deb12u7_mipsel.deb Files: b666526faaea490e5b7ed04f9f6743c8 857412 debug optional gnutls-bin-dbgsym_3.7.9-2+deb12u7_mipsel.deb 9ab81b3455512076c614ec7147753cd6 624428 net optional gnutls-bin_3.7.9-2+deb12u7_mipsel.deb 9e659feb426bb9f9073b7fbb66fb9c6e 11278 libs optional gnutls28_3.7.9-2+deb12u7_mipsel-buildd.buildinfo 9fa8afec76c210e8dc7b99ae7a11ddca 267384 debug optional guile-gnutls-dbgsym_3.7.9-2+deb12u7_mipsel.deb 699ce57ea745d96f06e0560ac9f9a8a2 449472 lisp optional guile-gnutls_3.7.9-2+deb12u7_mipsel.deb 3eb458662146964b011737b9c44fd3e1 93040 debug optional libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_mipsel.deb c146a80b80cb67b29c3308ddad9cd997 403496 libs optional libgnutls-dane0_3.7.9-2+deb12u7_mipsel.deb 931bbea022882329c80536c0e4c13bee 94072 debug optional libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_mipsel.deb 975023a19cd4ebe8e1bc355de0bf177e 403208 libs optional libgnutls-openssl27_3.7.9-2+deb12u7_mipsel.deb 45df640fbda7db6085136da3d4e76b47 1357148 libdevel optional libgnutls28-dev_3.7.9-2+deb12u7_mipsel.deb e34daa62927217f95227c63561e059ea 2018484 debug optional libgnutls30-dbgsym_3.7.9-2+deb12u7_mipsel.deb fa5d3d8852022c8b98c21e1fdb59b493 1235332 libs optional libgnutls30_3.7.9-2+deb12u7_mipsel.deb 929778f5922d6444adb74b2e3db0bddd 48092 debug optional libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_mipsel.deb e5ba56240028cb335439660f288b6333 12952 libs optional libgnutlsxx30_3.7.9-2+deb12u7_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyYUQCyzsgu940OiVpwP2OD8jZaoFAmoLfgUACgkQpwP2OD8j ZapcSQ//STBqNlcgVzQyHjlAEXOlyCcf2NPBcN3w31m1dcAOQITvEz66i8WbC2IX FXx7tMn++xhdiQ4duT9QLGH3eymH68ianuayRtT/kncxh3YubLlYkl61tGisNcHR +XE42AEPbDqTmDEHiOfsuSpo6lVNQLmOkLDc7V+sQ4YuqAVn0Aevlkw7XMXABL6z gQCuSS6aQYcK2TR6ABq4uLSgpyLbjuu9JorHcRKnN4XksPOAyV9MLaQ5CSWebnWL 9lwrZ7ChSOsr53eAHBLxQnrS2RFS7VHKcJ/LCj9g/Y8RM6ZqdXIDq1DwdImcBqho X8FjMJcjwfgzsUe+YLKkiaUG+O0Ob2uQFIhC1bGd6VVIipLvRCGbBhZoZoyw/hp7 zxa1d9Z7pUrhy3lcHpJziXUnWnAFXWbLGZ3L0KsNObFUejZS0394qeqDUxfaCVJP aT0PJfIWnREbTUhVsq8T5hpAcnEiG9DNYblrYjOs9zNjABGdVd8wi2XyEFSAPbYC DSyaSGtH4BqEPPrryWGHcPWTNvZVi+ZbLpgupBgheLDEQ5/PNc7oKB4mPm3Nt3XH byRqX8vd7kz9UmoT9E7Wl9sovPPsot4mxprw2qQMJkIdimpv+d0cVrO9NMP7fdFt aR8+zLlNEWdoyU3Y6oO9wRqdcpbfglUohiWdgjmX605r6p80gBs= =jQmF -----END PGP SIGNATURE-----