-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 15 May 2026 13:57:52 +0200 Source: gnutls28 Binary: gnutls-bin gnutls-bin-dbgsym guile-gnutls guile-gnutls-dbgsym libgnutls-dane0 libgnutls-dane0-dbgsym libgnutls-openssl27 libgnutls-openssl27-dbgsym libgnutls28-dev libgnutls30 libgnutls30-dbgsym libgnutlsxx30 libgnutlsxx30-dbgsym Architecture: ppc64el Version: 3.7.9-2+deb12u7 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Andreas Metzler Description: gnutls-bin - GNU TLS library - commandline utilities guile-gnutls - GNU TLS library - GNU Guile bindings libgnutls-dane0 - GNU TLS library - DANE security support libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper libgnutls28-dev - GNU TLS library - development files libgnutls30 - GNU TLS library - main runtime library libgnutlsxx30 - GNU TLS library - C++ runtime library Closes: 1135319 Changes: gnutls28 (3.7.9-2+deb12u7) bookworm-security; urgency=high . * Cherry-pick fixes from 3.8.13 release for oldstable. + This includes fixes for these issues: CVE-2026-3833 CVE-2026-5260 CVE-2026-5419 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015. + CVE-2026-3832 only applied to release 3.8.9 and later, no patch needed. + Patchset pulled from CentOS c8s (3.6.16), split into patchlets, unfuzzed, adapted for 3.7 (adds 72_0015_gnutls-3.6.16-1810-ocsp-truncated-eku.10.patch). Also added those patches from CentOS c9s (3.8.10) that are relevant for 3.7.9 (but where not for 3.6.16). Closes: #1135319 Checksums-Sha1: e45464dc73a5d7974c4060eb990ed9933ff51a9f 858268 gnutls-bin-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 7896979ce0a49d2452d51dd706629affd1ba42e5 641464 gnutls-bin_3.7.9-2+deb12u7_ppc64el.deb 3e1b93eaa34346cc8bc987dc417de248ab32c022 11534 gnutls28_3.7.9-2+deb12u7_ppc64el-buildd.buildinfo 933bba3874c368333779289e438c1514551839d1 267856 guile-gnutls-dbgsym_3.7.9-2+deb12u7_ppc64el.deb d39b466e5af8bf774e4a8ec1c9d6b46d8874f98c 464064 guile-gnutls_3.7.9-2+deb12u7_ppc64el.deb 72f9631b1fb10331ac3f96025b3fce9f7adb68e9 94716 libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_ppc64el.deb a12e8ba8e46c4d2bb06c529d20b8b683041bf3cc 410024 libgnutls-dane0_3.7.9-2+deb12u7_ppc64el.deb 14019fad6cf2aa054e87893acd49929190d40770 95776 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 9b438a693c215117de2d079f182e3d349b9267c5 409760 libgnutls-openssl27_3.7.9-2+deb12u7_ppc64el.deb 87004837a2006294c2b69c5674cdd05582823c39 1417488 libgnutls28-dev_3.7.9-2+deb12u7_ppc64el.deb 3613ee57fa3cabbc52cd98c59bc2390a98fdb95b 2068752 libgnutls30-dbgsym_3.7.9-2+deb12u7_ppc64el.deb ca157eaa2a12b9c36f0f1e0de1db6b304f34a418 1373972 libgnutls30_3.7.9-2+deb12u7_ppc64el.deb e21bd4f7b64ee15278de58c1741a76c6d1abd205 49936 libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_ppc64el.deb de3a4c2388247d41131b5cef55904d4c8bb1beac 14512 libgnutlsxx30_3.7.9-2+deb12u7_ppc64el.deb Checksums-Sha256: 264d25213dceb9e062d6a10ff73d8834f57117e240d47950ff360295ce3f22fb 858268 gnutls-bin-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 055a85456934ce228d17887b8f4b507a3be5590d7218e6ef8349c25555e3151c 641464 gnutls-bin_3.7.9-2+deb12u7_ppc64el.deb fb45ecc7a36ced4de973a390501d0effa458955860cd214f1a4df42398689e3a 11534 gnutls28_3.7.9-2+deb12u7_ppc64el-buildd.buildinfo cbd05fdc4b7da5ff73645e3c484091be5fde1ee615a3b4d2f1e3969f4c053bfc 267856 guile-gnutls-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 65be563514b2924c8b41ef8403d6cf980671a37226dc8fe435838edb98a6fdd9 464064 guile-gnutls_3.7.9-2+deb12u7_ppc64el.deb 9e9e82f13cb8ea9acec798afcf15583dcd647a518c637e29ad67b246d4c0ffeb 94716 libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_ppc64el.deb ad7a85a8a49deda42941aedf2e6a1d83e73fa6363a190dbcb0269b8282af6079 410024 libgnutls-dane0_3.7.9-2+deb12u7_ppc64el.deb 7d07171db6973d9bb59e092bd297130b0d4bb1d575f033adc0269a2d64d28947 95776 libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 46e1287cb19269158d9dd6a2d38b8ec631b68fabab0b6472e1865ed928be8fc8 409760 libgnutls-openssl27_3.7.9-2+deb12u7_ppc64el.deb 7de3509f74e479e4d8e64f082ef71925279eac98e69e1f04fb11571e4c6c3abb 1417488 libgnutls28-dev_3.7.9-2+deb12u7_ppc64el.deb 23e986e695e309503ff0ee654a7f1f04c3ec34a8e28d50bb4d9963c0b2a2309d 2068752 libgnutls30-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 01fa50c9ad16a988569ec838c5c07901c15f4e35ff780ad129952f327fd83e19 1373972 libgnutls30_3.7.9-2+deb12u7_ppc64el.deb 2f4114592173cf579743bfc6d70ec9b483714ebf1a73f759d62d395ee37c82f6 49936 libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_ppc64el.deb c9d37dc43eb44dc287fa7d58f59ad951c491680eacf6eb1c45714166c1807105 14512 libgnutlsxx30_3.7.9-2+deb12u7_ppc64el.deb Files: 31274d2ab41f0daa1e1c24f5223dff34 858268 debug optional gnutls-bin-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 0ad112a25769934dd3cdcd6536e61772 641464 net optional gnutls-bin_3.7.9-2+deb12u7_ppc64el.deb 79a0a2ebfec1de2c8afacfde04e87ee9 11534 libs optional gnutls28_3.7.9-2+deb12u7_ppc64el-buildd.buildinfo 8f6b0e60a5c2fae769d7809877ddc4e1 267856 debug optional guile-gnutls-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 59d1bcf022bb511843c743270a274bb9 464064 lisp optional guile-gnutls_3.7.9-2+deb12u7_ppc64el.deb 3390dc7f5ce1d9391f340aa8487fd0cf 94716 debug optional libgnutls-dane0-dbgsym_3.7.9-2+deb12u7_ppc64el.deb 78adb68efb495cce4b75d7ba9df9e265 410024 libs optional libgnutls-dane0_3.7.9-2+deb12u7_ppc64el.deb 4492d1e9e6a2498ef5b288809b4295b0 95776 debug optional libgnutls-openssl27-dbgsym_3.7.9-2+deb12u7_ppc64el.deb d3ee22694eca86643f7c59926b0755fb 409760 libs optional libgnutls-openssl27_3.7.9-2+deb12u7_ppc64el.deb 057c3981d63a6852596a411f27c56d29 1417488 libdevel optional libgnutls28-dev_3.7.9-2+deb12u7_ppc64el.deb 7622b19625c1f044b09f8a4a765ad598 2068752 debug optional libgnutls30-dbgsym_3.7.9-2+deb12u7_ppc64el.deb bd35486463e6d031707665b9538a309a 1373972 libs optional libgnutls30_3.7.9-2+deb12u7_ppc64el.deb 30531c13ee4a5267f7eebf5306344d49 49936 debug optional libgnutlsxx30-dbgsym_3.7.9-2+deb12u7_ppc64el.deb ccb90f76e675a36611b543137b5c59db 14512 libs optional libgnutlsxx30_3.7.9-2+deb12u7_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETLpi2USYGUNSlYhoNINNphgym2QFAmoJ9L4ACgkQNINNphgy m2QQOA/+JiX7qtWESgBk63QZBT3qakGQpBuUQmCJmz38EVprnPDsXyJ+wiPHjif2 WYSayvQbz0Guj2dWrOtRtGcqbhqz1XPtHarSrqmJmham4B3NnrU44yLRB7Z/8ngU YsfouiCyVO/vrjJplGXtY/xvCM+tpEYdMqDvlHqJBoMeUyR/+bHSQGMAq2wlNK27 XxEmAa6LUcrToy6VhJTFp1qAqXmnn4QnU2BOGg6QuvziKW9wWR9teyWHxdcVIKCO mCj0ZONM23hIw3kUJbJcbcYlbGRP528E9+oBFkMjOMFggelYoNPHPx/7tNL+a9s9 i1qfmyBCBVhE3SLOxtiRT+0yO06gGP76QnYiTQSoQ8dJlu1exrqWuqkqG1WdJEro 3k5uYFT2uXKPW2ZnGhh4mrSBHpVrgDoXdi2fqaqTqbmSpCTlEwOol9/xKZiJsFIs evNiJovo+8TVunYq7IaFp8lO+gBTU7oEHHsEcRGsOvBi5gHfbejU3dOHurUptOrg gJCa3pkWn1+rzlcZLLHGc+QU35mIRMdnTN6bvK5PgnaFkK63T/Tc3VkQYXtXL6Av ZbsEZcEHCxIGyw01qxlUyUvhgPZUOE+nhwm1bV1e5o2J8IW05driqBQOwdVgL0Hf jP4htj9B4KU6XiTcsz3pgeyW0I6lrdYuJE6VEMw1H2hl3NHHhKc= =XxXE -----END PGP SIGNATURE-----