-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 16:23:22 +0200 Source: nghttp2 Binary: libnghttp2-14 libnghttp2-14-dbgsym libnghttp2-dev nghttp2-client nghttp2-client-dbgsym nghttp2-proxy nghttp2-proxy-dbgsym nghttp2-server nghttp2-server-dbgsym Architecture: armel Version: 1.52.0-1+deb12u3 Distribution: bookworm-security Urgency: high Maintainer: armel Build Daemon (arm-ubc-04) Changed-By: Lukas Märdian Description: libnghttp2-14 - library implementing HTTP/2 protocol (shared library) libnghttp2-dev - library implementing HTTP/2 protocol (development files) nghttp2-client - client implementing HTTP/2 protocol nghttp2-proxy - reverse proxy implementing HTTP/2 protocol nghttp2-server - server implementing HTTP/2 protocol Closes: 1131369 Changes: nghttp2 (1.52.0-1+deb12u3) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-27135 (Closes: #1131369) Fix missing iframe->state validations to avoid assertion failure. * Add test for CVE-2026-27135 (cherry-picked from upstream c619c7b) Checksums-Sha1: 18a48cd58789606d0090c91d8597cff342ab7e53 212660 libnghttp2-14-dbgsym_1.52.0-1+deb12u3_armel.deb 2e4f46428c8a46e1411b54956e415d923882e909 62332 libnghttp2-14_1.52.0-1+deb12u3_armel.deb 67efe464f46839263286cb51b5924acca884d5c0 99708 libnghttp2-dev_1.52.0-1+deb12u3_armel.deb eb8dc01fcdae0cf6ecce80a8aca1835daf733578 1866184 nghttp2-client-dbgsym_1.52.0-1+deb12u3_armel.deb 695d59d720e69977d7c36e4344e1ab1fd6462719 149720 nghttp2-client_1.52.0-1+deb12u3_armel.deb 55583d5bd6b454b3f942df85bbacf0ca28087ddb 5709016 nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_armel.deb e7e99c8b5a806a14d44945870ec51bcd16076df3 344844 nghttp2-proxy_1.52.0-1+deb12u3_armel.deb d38e633af27a133a3a977bbed14e06543389313c 945540 nghttp2-server-dbgsym_1.52.0-1+deb12u3_armel.deb 0a8982ab250c1340b059fe1846215f36496878dc 86020 nghttp2-server_1.52.0-1+deb12u3_armel.deb 52f8dc71c032aaa8f27feae9e8edaf8cdbe0ef48 8921 nghttp2_1.52.0-1+deb12u3_armel-buildd.buildinfo Checksums-Sha256: dde8ad972a7e7d5599bb9f90060e7884b26dddeeea5153391825ff6736457765 212660 libnghttp2-14-dbgsym_1.52.0-1+deb12u3_armel.deb 2975591fc95e8d23cb1fa2c2496bc2533164912f847aea730b9832ea90898a34 62332 libnghttp2-14_1.52.0-1+deb12u3_armel.deb a3db35e1698b48612ea696bfa900434e2101b5f6842dfc5efdf2868f80eae7ec 99708 libnghttp2-dev_1.52.0-1+deb12u3_armel.deb 4ebd057a9d47d8c41c0fbd192eec0c98885a64794b07d052eb2ca57c998ed4e7 1866184 nghttp2-client-dbgsym_1.52.0-1+deb12u3_armel.deb 872958f445472c2df69ee0103c6444a27b4f13f649b2a63dfc5a267e8e11298e 149720 nghttp2-client_1.52.0-1+deb12u3_armel.deb 021af1c4ef61cea9df95b66959b6479e7e6aad62d83b5157306b83b2f8f48d12 5709016 nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_armel.deb 9227e34916777b5e8973381cb1b7507bfef1696ea8346289a8b78ae1d3407e16 344844 nghttp2-proxy_1.52.0-1+deb12u3_armel.deb e3b52c8b2739396b704363fdd9e54d3b160bc3bfb979806e5d3614f45230b156 945540 nghttp2-server-dbgsym_1.52.0-1+deb12u3_armel.deb 0d661d281557d711e7b6f19a249dde42c2f9829f42412aa0cd4b23ea947e759c 86020 nghttp2-server_1.52.0-1+deb12u3_armel.deb 0ed9f23a21d1ed8c3203e69b0ec673f81a319030a71f9a88895c9d1ac74a6930 8921 nghttp2_1.52.0-1+deb12u3_armel-buildd.buildinfo Files: 22b897344531a9c8796c7446bc8c5b69 212660 debug optional libnghttp2-14-dbgsym_1.52.0-1+deb12u3_armel.deb 2cd465e9e13d2d689c156ab40b311847 62332 libs optional libnghttp2-14_1.52.0-1+deb12u3_armel.deb 76e0ffb3a5cf73af6e4d50556ca69757 99708 libdevel optional libnghttp2-dev_1.52.0-1+deb12u3_armel.deb 05a1e1b5432d78a90371b4b91840322a 1866184 debug optional nghttp2-client-dbgsym_1.52.0-1+deb12u3_armel.deb 9d98e89654a5476aa9a582fa65c7c583 149720 httpd optional nghttp2-client_1.52.0-1+deb12u3_armel.deb d240d139055183066517377d710c42fc 5709016 debug optional nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_armel.deb f64a87caa57c31e858c88f9773b9fa55 344844 httpd optional nghttp2-proxy_1.52.0-1+deb12u3_armel.deb 0bd5d7e08889a152b02b80af446df950 945540 debug optional nghttp2-server-dbgsym_1.52.0-1+deb12u3_armel.deb 5772f1ec2f58be90ac24719c97a80137 86020 httpd optional nghttp2-server_1.52.0-1+deb12u3_armel.deb db5d1f70b43978a7b3ea67a13e4a6472 8921 httpd optional nghttp2_1.52.0-1+deb12u3_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEECx5fXZYVNP9tMtwlK1PZBedPspoFAmoEbjoACgkQK1PZBedP spoWpQ/7BoX3Gvyd4tXlcvHXLngSG+wDpCde7AffkublIXwZHFwRbwG76UG7bSaM 88VAlzTsqvIfUn9PjRH3XZZ28/VEWRz/h36CnZyv1nJTU7MyZNZJ9KLWYcbfkSxE kAPlHVkfW3wpYdvC61HqbFyswKlEwT7Flqps1wCD5jAfQ8cHI4KbRlB8Mns6NxME ECUGtli9aOgNLJRktMc1rVHo8ahvl4UbRf9XZN7IlI9oN5DQeuiDxNMOLoNHH7w9 SmkTByRlvxvf2wHamSiBNulHJAyWAy53D3IArFWX7W+lDPHLBlBQqKKZO3cNT9EA KMQUxvdArCA6InKLDpqQ9P7H3xxja67DhmtRmnWI/GjVsJsY77lYm3jfBgyWBx3m pOEqL3alrZE1e6aq8OyeBvv/j0ONp56+2lgh+uMd7KElx5oQRU+0WP4a3Ro+jFCw 1tiQLTOldFaHe2FaVg+ohHN7vckwl6LDZl031NOdsJDKAglPVMG75rbbb6BzEtsG UueR4MFN9uVON4ZBGj7VE9bnvbzk9wG0wKSLKaYOPx94WByWswMATFMyyT8LwnQs 0ZuMXLGLiGDWpLps7692++gSPic4KtZ2wS+MGZEIrFqU/jwPQ5WknhVBT3dXUbyU /oU02ENnwCQa1eiuW+Ac3+QSO+jVSY/+ZPd8AbQFv5T+zV1WGCM= =jQFU -----END PGP SIGNATURE-----