-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 16:23:22 +0200 Source: nghttp2 Binary: libnghttp2-14 libnghttp2-14-dbgsym libnghttp2-dev nghttp2-client nghttp2-client-dbgsym nghttp2-proxy nghttp2-proxy-dbgsym nghttp2-server nghttp2-server-dbgsym Architecture: arm64 Version: 1.52.0-1+deb12u3 Distribution: bookworm-security Urgency: high Maintainer: arm64 Build Daemon (arm-conova-04) Changed-By: Lukas Märdian Description: libnghttp2-14 - library implementing HTTP/2 protocol (shared library) libnghttp2-dev - library implementing HTTP/2 protocol (development files) nghttp2-client - client implementing HTTP/2 protocol nghttp2-proxy - reverse proxy implementing HTTP/2 protocol nghttp2-server - server implementing HTTP/2 protocol Closes: 1131369 Changes: nghttp2 (1.52.0-1+deb12u3) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-27135 (Closes: #1131369) Fix missing iframe->state validations to avoid assertion failure. * Add test for CVE-2026-27135 (cherry-picked from upstream c619c7b) Checksums-Sha1: febe9fca95a25e3f06eb55a5895e316ebac335f0 219912 libnghttp2-14-dbgsym_1.52.0-1+deb12u3_arm64.deb 3440c00264f13cf95cea2665fe80a9f48fce1381 68976 libnghttp2-14_1.52.0-1+deb12u3_arm64.deb aaafc94cdc25a4d4d0405cfbb4e680afebe42ab7 107580 libnghttp2-dev_1.52.0-1+deb12u3_arm64.deb 52c6767cfc641194eb9ff1d362d375a3cf62b176 1973908 nghttp2-client-dbgsym_1.52.0-1+deb12u3_arm64.deb 48f509669b8c9a79e91406b879f563e624e2e20e 155692 nghttp2-client_1.52.0-1+deb12u3_arm64.deb 89fb1e9efafd5d49b9c49c411c3d7f5d26015be6 5758172 nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_arm64.deb 4318959ffb040e79e14ec8159d40dfd3664c6e98 352756 nghttp2-proxy_1.52.0-1+deb12u3_arm64.deb f2b746e51aaa928a724a6a6f4e329f0bb764227f 936076 nghttp2-server-dbgsym_1.52.0-1+deb12u3_arm64.deb 6263e035e3ac7205736ff777400c5bff9aec0e28 91172 nghttp2-server_1.52.0-1+deb12u3_arm64.deb ca63d017fb68d22b3d823331c4825ee60edfe303 9082 nghttp2_1.52.0-1+deb12u3_arm64-buildd.buildinfo Checksums-Sha256: 3058c2e579cdfd4a2daa1f87837972b3417edf7709d7eb9213e38aed0a030d6e 219912 libnghttp2-14-dbgsym_1.52.0-1+deb12u3_arm64.deb 7767833033739adb2e2e374f2c4b36134d9f36fcdfe8e2aab7029bf850146da9 68976 libnghttp2-14_1.52.0-1+deb12u3_arm64.deb db97f087e25f6ca858fb515c8708286b1e5a79f7abb5849ac172abc39d73f481 107580 libnghttp2-dev_1.52.0-1+deb12u3_arm64.deb 944d6855672f578909d6110623997c695f1587ee4067f86023f65f408d122d63 1973908 nghttp2-client-dbgsym_1.52.0-1+deb12u3_arm64.deb f5631a8b496341770ec3bd832e5573f69a77da912d111be45237ba54f1696fdc 155692 nghttp2-client_1.52.0-1+deb12u3_arm64.deb edcbf94d03de1887b8573f279b2a1c45ccb1bd7f60492d012bada99ddfa976ab 5758172 nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_arm64.deb 285c1a51d26327fc239824bbdbcfde6c452b2e31e94f2a41d9d9468ac72f3e18 352756 nghttp2-proxy_1.52.0-1+deb12u3_arm64.deb 2bcaf94b0fc1771f248c6ef84c11869755563c0882625f060f8f89610a46445a 936076 nghttp2-server-dbgsym_1.52.0-1+deb12u3_arm64.deb 5f5f24f3738cf0c0c484069de4dd4c06dfb3c4a9847dc5377cfe326fc3d9de80 91172 nghttp2-server_1.52.0-1+deb12u3_arm64.deb f9b2974f77cddb2d5290ffdef7e8c59348ec335d75df5385f469a1e47ff35598 9082 nghttp2_1.52.0-1+deb12u3_arm64-buildd.buildinfo Files: fad981815e1bdb77002951110b78efff 219912 debug optional libnghttp2-14-dbgsym_1.52.0-1+deb12u3_arm64.deb c84a66e19c9fee0d0f6e5b16d7b6698f 68976 libs optional libnghttp2-14_1.52.0-1+deb12u3_arm64.deb e88549776c678fc6660b5f5317513f52 107580 libdevel optional libnghttp2-dev_1.52.0-1+deb12u3_arm64.deb e62a51fd888c39bf1539da837be9fc16 1973908 debug optional nghttp2-client-dbgsym_1.52.0-1+deb12u3_arm64.deb 857a09259287077463c3088e1871f7e3 155692 httpd optional nghttp2-client_1.52.0-1+deb12u3_arm64.deb 3c48c36792a226f2e8065e8b6ca30448 5758172 debug optional nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_arm64.deb 81448138da892d37e61ace9b8c499edc 352756 httpd optional nghttp2-proxy_1.52.0-1+deb12u3_arm64.deb d04df303bd19a7f17223290bf1f808eb 936076 debug optional nghttp2-server-dbgsym_1.52.0-1+deb12u3_arm64.deb 68fa061fb79fab0dddc0839f66990b56 91172 httpd optional nghttp2-server_1.52.0-1+deb12u3_arm64.deb ade8e9779e3ff923f0dcad38dc583a10 9082 httpd optional nghttp2_1.52.0-1+deb12u3_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmoEbicACgkQScpU3dYu lLhW2hAApaVcDYMVdETHnIgu+Bh9RtHGy/5rawRhMV2nMsSKWgtRJTXjAeAMQqra ncRuMJ2hY6noPs7pg4X841FgfGaixraVZk/MYLLC1EBPyRvQTIfozy2bXxio5gWC 4kHqcIT4xkuq9dOxPSiAHxP3YzUs8KbWMHXluolVUV+cV71knhspPRxThEjqfAcE pM2eUB0rNpb6tAakslBiuTF2faxJcsRlfDpp1MUuckTvVJFqHR1RM0IvmcmhiWVR TD5m6MGQgFMZ1rIcuAbQJAxrJjWdC56wtYBuNj5AAhqtoKG6cLJ3moELuGffKpfd 4xgawhMU4WJE2LS8aNhrsWz7TnQRWl7bH9FGxV/FoV+6Clzc6wwfQ9Rko0Nk+kXY yEqon1FtG3WtVQt3TkEUVq8atutnRz9k77OnDzeyAGyPWtbO4a+KkoWZRF1jHLIb O9UJMYiPrWt/LYuPDSrEVZ9n9ahyQA6vgJiOI+traL0sCyRDAzjqMY6jxwKUqInu A9y8jyBfv00uKKnIqml9Jx+/e1dlY1dOuyHkD7P/VNYgZnZq0l98gK3vco06iGGN ZXBwEyBjcKs2eNTMAf8qHz8GM37n/ojsJVoT4XErlXC0wsx2swrPGS3km5yJGtNu R1OEYCW2zCpJ750XE+TutGUOIh6ITRwiCZChPw3MHwmkpcay+SY= =Gfmc -----END PGP SIGNATURE-----