Publishing details
Changelog
openssl (3.5.5-ok8) huanghe; urgency=medium
* CVE-2026-14457, Handle signature_algorithms_cert extension in key-only context.
* CVE-2026-18798, QUIC Server May Trigger Double Free When Processing INITIAL Packet
* CVE-2026-54874,Excessive Memory Use Buffering DTLS Records for a Future Epoch
* CVE-2026-63072, Heap Buffer Overflow in CMS Key Unwrapping
* CVE-2026-63073,Untrusted Sender DN Used as Format String in CMP Response Validation
* CVE-2026-63074, CMP Indefinite Cache Growth of ExtraCerts
* CVE-2026-63075,QUIC ACK-only Packet Retention Can Cause Memory Exhaustion
* CVE-2026-63076,Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
-- songjuntao <email address hidden> Mon, 31 Aug 2026 10:35:48 +0800
Builds
Built packages
-
libcrypto3-udeb
Secure Sockets Layer toolkit - libcrypto udeb
-
libssl-dev
Secure Sockets Layer toolkit - development files
-
libssl-doc
Secure Sockets Layer toolkit - development documentation
-
libssl3-udeb
ssl shared library - udeb
-
libssl3t64
Secure Sockets Layer toolkit - shared libraries
-
libssl3t64-dbgsym
debug symbols for libssl3t64
-
openssl
Secure Sockets Layer toolkit - cryptographic utility
-
openssl-dbgsym
debug symbols for openssl
-
openssl-provider-legacy
Secure Sockets Layer toolkit - cryptographic utility
-
openssl-provider-legacy-dbgsym
debug symbols for openssl-provider-legacy
Package files