-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 21 Nov 2025 00:45:17 +0100 Source: openvpn Binary: openvpn openvpn-dbgsym Architecture: ppc64el Version: 2.6.14-1+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Bernhard Schmidt Description: openvpn - virtual private network daemon Closes: 1114249 1121086 Changes: openvpn (2.6.14-1+deb13u1) trixie-security; urgency=medium . * Cherry-pick patches for CVE-2025-13086 - check-message-id.patch: Check message id/acked ids too when doing sessionid cookie checks - bugfix for floating client problem, code prequesite for the CVE patch to apply - CVE-2025-13086.patch: Fix memcmp check for the hmac verification in the 3way handshake being inverted (Closes: #1121086) * fix-ftbfs-kernel-6.16.patch: Fix compilation against 6.16+ kernel headers (Closes: #1114249) * d/gbp.conf: set debian-branch for trixie Checksums-Sha1: 2780367e4194aba29fbb003118119b4c16c664c1 1325328 openvpn-dbgsym_2.6.14-1+deb13u1_ppc64el.deb d525cc630ce917b82cd212c3d091d764e45050da 7104 openvpn_2.6.14-1+deb13u1_ppc64el-buildd.buildinfo a5d07efa7c29d7150fc756356bb72b5238c27451 687552 openvpn_2.6.14-1+deb13u1_ppc64el.deb Checksums-Sha256: 8dfcd66d4a875d8852e348688c73b1aa3013e9dba6461083d88eb549d4109b04 1325328 openvpn-dbgsym_2.6.14-1+deb13u1_ppc64el.deb c9a4dcf10f0aa60e45e745e872e7ce960ff5da653b35be5a6ff526ef12fe6b3a 7104 openvpn_2.6.14-1+deb13u1_ppc64el-buildd.buildinfo c01dcffda38a5f6ca411d895a07eb561ec911a3e29786fde35c5ac1e21acce28 687552 openvpn_2.6.14-1+deb13u1_ppc64el.deb Files: 86d540d856ce34f8c6229b6bf37731d5 1325328 debug optional openvpn-dbgsym_2.6.14-1+deb13u1_ppc64el.deb 6ae61a4f77cfd211e3dc987f0dcada49 7104 net optional openvpn_2.6.14-1+deb13u1_ppc64el-buildd.buildinfo e83a4d6e55d111f6a178e259c9548ba0 687552 net optional openvpn_2.6.14-1+deb13u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZAv/jpGRqS40qyb11oy1TpxF0ZAFAmksyCkACgkQ1oy1TpxF 0ZCABxAAjEeutLxa0C0RWZnjTV3UgXV9DbiHadsLy84R9j4zZNMZjvkWCIVbQUOl rNm3pVzy5ukroDycGX/9O3GOCUdBa3RHusgZKh4ZSdRyGUOFfZMTGpKXU0nHmh/k ac7/Y3qeFPSzc1+wqVGzinfHy7RkR6RsQWHtvTEUdIwXhfREPEKypUdYc7jzHRb8 F3dkZJmV7LO2XLbX0ZeapDH+OC9JGHH4ZEfAttlRnIGeO4aL1XU6cyBKv/bTsJ++ ciTWfXDV7XLaHs93GJ/KaP+9FHy9QenvjtUQB1F15UVtbVmpcZWEFoCCeqHfWLDN mULmBlzbKC4xO2k0pOildAxlHMdIN5U8i1NI83GnTcTeYlc8D60LpkFomJ9mNRPL u4HJzwIVrPhyZW9pc0zOjN8L/fD91j7IhZdxlfdLnuHCgxfydPKrulRGU3a2wi1I Zc9KjwTxlZNW6gij0vm8TztYr2qnE3JIUoivU2eHUlS0lRHw3VxOuh82flqhfemd HlKooM6L/e0YACsHi35YMR1Ms+9X0MBXla5gnH3t9ndBwpL6/NBoL+LzFol/MjKq za84YLjndidSS+DtBbTHxfVpAOCwjG0o8weKJInIDSGtDjyT1GHzLtqe0tQssxNo o1Oi/kjUzoA8Vhln9vngW25Aoa7x3TZFEC7Sv9Guq4zEmq30Wt0= =OAOl -----END PGP SIGNATURE-----