-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Jan 2026 16:01:59 +0100 Source: openssl Binary: libssl-doc Architecture: all Version: 3.0.18-1~deb12u2 Distribution: bookworm-security Urgency: medium Maintainer: all Build Daemon (x86-csail-02) Changed-By: Sebastian Andrzej Siewior Description: libssl-doc - Secure Sockets Layer toolkit - development documentation Changes: openssl (3.0.18-1~deb12u2) bookworm-security; urgency=medium . * CVE-2025-15467 (Stack buffer overflow in CMS AuthEnvelopedData parsing) * CVE-2025-68160 (Heap out-of-bounds write in BIO_f_linebuffer on short writes) * CVE-2025-69418 (Unauthenticated/unencrypted trailing bytes with low-level OCB function calls) * CVE-2025-69419 (Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion) * CVE-2025-69420 (Missing ASN1_TYPE validation in TS_RESP_verify_response() function) * CVE-2025-69421 (NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function) * CVE-2026-22795 (Missing ASN1_TYPE validation in PKCS#12 parsing) * CVE-2026-22796 (ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function) Checksums-Sha1: d6c0a9551d9fa4cb9249b959b5664dc655c99b1f 2387440 libssl-doc_3.0.18-1~deb12u2_all.deb 3be08045c99907e035ab609a4f6f7e4761923f76 6031 openssl_3.0.18-1~deb12u2_all-buildd.buildinfo Checksums-Sha256: e30c0af177d751e89e9af4aee33e34c83dd1d6eae39c8b8f34ee26e511e0a427 2387440 libssl-doc_3.0.18-1~deb12u2_all.deb ae808b875a40bdb0ff2c0f26a931318922f9dd5633348f0448ddbe1537a14129 6031 openssl_3.0.18-1~deb12u2_all-buildd.buildinfo Files: 7fc4eaf2a8d0f0cb21c4bbbde17cfe8e 2387440 doc optional libssl-doc_3.0.18-1~deb12u2_all.deb 664ccb9effb7c186b4fc7957f5881f57 6031 utils optional openssl_3.0.18-1~deb12u2_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEELusn8jY95Sf7obGlx30Wh8LXl/YFAml0890ACgkQx30Wh8LX l/awrBAAqjQhNrOCxtaHNEltdfp9O+aiagg0P2sIq8iFUSJI7+/8VjxiS24DbRjT Lxql/wLJCBPmqXYdbtvjhEFgex12Hh1ghby4+tQ/Ua7fJJ0N0ZawLfe6RjixZPNZ MAGRw088oKv/XbJs46rQWg8IODsuoZFZB/NOLifm+5kXNvOMQ5pGygHQbcASZ5aM ApFGDZHCfCUCRKVUadNKMLysy4fEwoqCFtjiUh7fvV9HeFKxo3FbzACVgas/q2/U v1WASiHnj89Xk32uc/4xqpysimdxdkDGuK3wOSsMgLZOXqxT5M1U9go8G5J+Q0he IFBKQId/52EhBnv23KajvnjwL/26BZySfnQFI31j6BXJFGm0QWE7hlF5csj//KIn UnFCkqavac6Wf84L8TaicMZIBmCGcid8a3K98CQ566HXGU3mS6ogE/ELs27nJT9F /C58L5Dwkj3+kpa7jpC6trsjrRx/Ir2CR6SzOq66cahwXzGTOqYqvjau1BxonYp+ 6kS5+70Q9foy+rWMXZluUtLHMhTyuZa5RiyflrNYDFbYTMFjVoabEAb3v3vW2RMk DOwVz8k6Zm7OOyDh5L5HGG83tA9aULoXwe8MZgbAaznMZAKvhWQXWqQrLK3CVhcc 7aoMoop5c94rJUTeu5RhgniqJhZaW8bhmVKU+kWaKcLUqBHHpOQ= =o9s5 -----END PGP SIGNATURE-----