-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 29 Dec 2025 18:23:22 +0100 Source: libcoap3 Architecture: source Version: 4.3.4-1.1+deb13u2 Distribution: trixie Urgency: medium Maintainer: Debian IoT Maintainers Changed-By: Thorsten Alteholz Closes: 1121415 1122290 Changes: libcoap3 (4.3.4-1.1+deb13u2) trixie; urgency=medium . * CVE-2025-59391 (Closes: #1122290) fix OSCORE configuration file parsing issue * CVE-2025-65493 (Closes: 1121415) fix NULL pointer dereference * CVE-2025-65494 fix NULL pointer dereference * CVE-2025-65495 fix integer signedness * CVE-2025-65496 fix NULL pointer dereference * CVE-2025-65497 fix NULL pointer dereference * CVE-2025-65498 fix NULL pointer dereference * CVE-2025-65499 fix array index error * CVE-2025-65500 fix NULL pointer dereference * CVE-2025-65501 fix NULL pointer dereference Checksums-Sha1: 42202843fdf5b24f067c3a46e566ff3b448804c3 2421 libcoap3_4.3.4-1.1+deb13u2.dsc b013aae51d438d6c79773a324dd6c66bc8fa8614 528071 libcoap3_4.3.4.orig.tar.bz2 da7dbcc09fb24f6b72c4c01050fabe5340934c52 12216 libcoap3_4.3.4-1.1+deb13u2.debian.tar.xz f619265617451396b3b4c5bc6dd9ee8ad18d74d3 11161 libcoap3_4.3.4-1.1+deb13u2_amd64.buildinfo Checksums-Sha256: 373f508f8506ff2641b5a34709a79362eda8c3334ad0659431d71e5bd3152a5a 2421 libcoap3_4.3.4-1.1+deb13u2.dsc a5abadd4b1e9a97c46197451326aa206c035362f0f15e7f4bb8846d7b8fcfb65 528071 libcoap3_4.3.4.orig.tar.bz2 c1731e59ea4e773e887fb0c98fbeb4ae779c775f83b45dce0431677d4d8afe6e 12216 libcoap3_4.3.4-1.1+deb13u2.debian.tar.xz 43d85d22d3a0fff6d0a9ae2b7a3495e621affae0934e5466518d3e0f01cb810e 11161 libcoap3_4.3.4-1.1+deb13u2_amd64.buildinfo Files: 8f0019d99536f246cf2c69ee2ae62602 2421 libs optional libcoap3_4.3.4-1.1+deb13u2.dsc 69a0afa3a2af381a45af7ea379220468 528071 libs optional libcoap3_4.3.4.orig.tar.bz2 4345213f6d1ebd8201f4e887b715042d 12216 libs optional libcoap3_4.3.4-1.1+deb13u2.debian.tar.xz 465f32d0953fdb386e13dfea2c6a8f93 11161 libs optional libcoap3_4.3.4-1.1+deb13u2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmlWrc1fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR1f2D/97AU4gWFGfyX7bq7S5KienSAYqLHr7 5pqZ9OMrK/Q/FSXP5MrtNY8kCZKaFqD2VYi/4tLkuRGpytpcRH34C1DN5bVEZJwA 1lA0h/ixUA8cr3GG9xNbXVu9D9Xk+xvwLKBSm+QNHnf05dJc1a/oIdMnDXTHdXkt 7PtTxFRpDp++h6dwrx2kDT9AX/57h48Z4BepR6iRxl7h0gHccrmZUwP40GGre3vd bIegYf+anPrXQqYWEyE4EUjgIfmKtcaB2QH0S6H8ys44Bv2cAMJvMC0WFpXug+x6 pXyM2dyHsewJldlKHUCEKLb9bomYyNWpixfBGcljs7gCDRHVS7imAZENyNugPYk2 FhpPmuhmWpJkKcLq7AX1Ih8ej7uecVKQ+7oQ6qQhNRwo7HbIsefjGp9k7vc8WXnL 8CWL/QqRKW5T2VH8qn/FdA3Izj+CdjGLfTSCTLPp9Wb/kxWQWr2z6JtBq3eK+ZUk 9vAIwztRrx5zqJslntpGNiDFHqSnlO0u+zxgC0rFmY/OehtSbfaWEPqgbpGLkRo5 EwTI3dzNCcljIRmemXn5lelh3oFEJeLGPiFMacpzFhjhNGoVyAKifipmr9Z+rTDK GQO7kNhrR9G81CZCvyhk9i67t88UbJzpKBUFswOZeDGjW6aKzaSvnDOo4SSIW9mn B0zVYkt/ano5Eg== =ANWd -----END PGP SIGNATURE-----