-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 16:23:22 +0200 Source: nghttp2 Binary: libnghttp2-14 libnghttp2-14-dbgsym libnghttp2-dev nghttp2-client nghttp2-client-dbgsym nghttp2-proxy nghttp2-proxy-dbgsym nghttp2-server nghttp2-server-dbgsym Architecture: s390x Version: 1.52.0-1+deb12u3 Distribution: bookworm-security Urgency: high Maintainer: s390x Build Daemon (ziehrer) Changed-By: Lukas Märdian Description: libnghttp2-14 - library implementing HTTP/2 protocol (shared library) libnghttp2-dev - library implementing HTTP/2 protocol (development files) nghttp2-client - client implementing HTTP/2 protocol nghttp2-proxy - reverse proxy implementing HTTP/2 protocol nghttp2-server - server implementing HTTP/2 protocol Closes: 1131369 Changes: nghttp2 (1.52.0-1+deb12u3) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-27135 (Closes: #1131369) Fix missing iframe->state validations to avoid assertion failure. * Add test for CVE-2026-27135 (cherry-picked from upstream c619c7b) Checksums-Sha1: 1acc462743aea64d9c51e13bf3a08f5a47de58f8 216128 libnghttp2-14-dbgsym_1.52.0-1+deb12u3_s390x.deb 960b0e287d39b67fc6eae77a51c2448bc50ed1ae 68148 libnghttp2-14_1.52.0-1+deb12u3_s390x.deb 023df0fa6b8ed0c2029d00199a3959750217c9cf 105368 libnghttp2-dev_1.52.0-1+deb12u3_s390x.deb 425d9d5c64b63aa931f24c2136945cb416449bc4 1875264 nghttp2-client-dbgsym_1.52.0-1+deb12u3_s390x.deb 60c7e15515d2ea53e4144b54a18fc9481cafad1e 159540 nghttp2-client_1.52.0-1+deb12u3_s390x.deb 7b6f825c12574320dfc82356c71a2744bf756953 5749596 nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_s390x.deb e931af37f43a3fa2b61cf6056ed336f6e6660d0b 354904 nghttp2-proxy_1.52.0-1+deb12u3_s390x.deb ea39d24492cce3b72b66c043888b3e81445ce9eb 940776 nghttp2-server-dbgsym_1.52.0-1+deb12u3_s390x.deb 22b94b0d7cdf88b72dc92e879a6c4a170f2f3fb6 92292 nghttp2-server_1.52.0-1+deb12u3_s390x.deb 901e544f4a6c28292f42f8bad3deead8792fdb24 8954 nghttp2_1.52.0-1+deb12u3_s390x-buildd.buildinfo Checksums-Sha256: 90ca8316b4f898ab04e884a8d2b4fb65110f08b1a8d756ecba2840f96f4d5049 216128 libnghttp2-14-dbgsym_1.52.0-1+deb12u3_s390x.deb 868e59bc2042442dbe89fc3f2bc4854938b6901df52bcdb320fd3d153f548073 68148 libnghttp2-14_1.52.0-1+deb12u3_s390x.deb 550a8fee3c41d6958c582250a90fda23162f718e0bb6e55e67fb19a66bd6ebff 105368 libnghttp2-dev_1.52.0-1+deb12u3_s390x.deb e2d23500d1c6c61a7475105b0c011f2594c9d99dce570936203704ed383ec665 1875264 nghttp2-client-dbgsym_1.52.0-1+deb12u3_s390x.deb 68d78138ff8dd383347168dd241eb614bf153d064785eed4603505aee9faea80 159540 nghttp2-client_1.52.0-1+deb12u3_s390x.deb 53332d6e5269b9eadc367a54253999cc85d5168fbe5b94e16dffeb1283cecb52 5749596 nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_s390x.deb 1fcd55a48953983e238d49a04a1f0683c6c8f92f51a3d04e2328a992b129c7a2 354904 nghttp2-proxy_1.52.0-1+deb12u3_s390x.deb d52caf0a988e7c4637a03a7332e24846301b743414e22ecd3b81fc2b4b72eb0a 940776 nghttp2-server-dbgsym_1.52.0-1+deb12u3_s390x.deb bafc7c52c45f6ea0e507cd7bb1c34eb741ead5c75e5dcbf680a23a7e0321f79d 92292 nghttp2-server_1.52.0-1+deb12u3_s390x.deb 778626592432b092f621d75f94076bb36a388ed4d1b02aa2b12cf7b2646201f9 8954 nghttp2_1.52.0-1+deb12u3_s390x-buildd.buildinfo Files: 33ad38554dbb049bdb3dccbaca69f6c6 216128 debug optional libnghttp2-14-dbgsym_1.52.0-1+deb12u3_s390x.deb ea10b77d71a7bef3ba897b94a188dfd3 68148 libs optional libnghttp2-14_1.52.0-1+deb12u3_s390x.deb bf90e232ca43f795157703ca6e310849 105368 libdevel optional libnghttp2-dev_1.52.0-1+deb12u3_s390x.deb a045baf236cba58c4356f5160574b882 1875264 debug optional nghttp2-client-dbgsym_1.52.0-1+deb12u3_s390x.deb ac286ba159f6a2794d23fa1bb7e37dd3 159540 httpd optional nghttp2-client_1.52.0-1+deb12u3_s390x.deb 6bcc9537f7aee6f5f90c29ef193f7e2b 5749596 debug optional nghttp2-proxy-dbgsym_1.52.0-1+deb12u3_s390x.deb 34712b4dffd8c33940162679dc40cd52 354904 httpd optional nghttp2-proxy_1.52.0-1+deb12u3_s390x.deb f544aee645ae4bc344e99c4ecbb9d58f 940776 debug optional nghttp2-server-dbgsym_1.52.0-1+deb12u3_s390x.deb 9ce78dcf9803a16c93f21c532c78386e 92292 httpd optional nghttp2-server_1.52.0-1+deb12u3_s390x.deb dc40e9df748d021eb1ec95e8c84de262 8954 httpd optional nghttp2_1.52.0-1+deb12u3_s390x-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEl0BM/nR+Oj597wRWMWUFebkHnoQFAmoEbi4ACgkQMWUFebkH noSx6w/9EDE64svfKw4KP7/EgxeHSHLvpiMTnpzzYERrS0iqMIW87S73LxsGD28B HFSEE60CKvlCT3YalQJLgoJDOUwkozkKZo0v/hadUS2VijNydQa9UPl005gcSqne 6GXVX2GU0bBfWvCYeUmr1JxDE3RKp+4VeUkxEWMDi3fz4Pkv0muk2ez8AxO/XVJA nawtRTAYkgoD0K8mKM0Pi8RUe2/KZ6zLwKkW2+Eq+/0gWNAHir9TPhIWjIWnDL5B NpQEZwdwE/0Q7H8qvc/WEOGJN114Q7yGIAw7/lkKvvGDoJmN9haBQFTbXYGLfbm5 /VJkgBUo816nC3jH2SosWac1VcwFI6Tp1uL6W32LZOv6XspXwMPP7jchGN3b4If2 06EA7DtwhC7CjNf1jcUY8aSrGVVk8js9kR1Xlp2chQcJPH3PfQqTo7dm1bR2H8JZ 5LYTKjOf3pE4TIdiyl7MR4hWj6ZGURcD/X0/8pprUrVPcUyr4uSMsrt7n04ZrL1/ ZEdR9+OIf17DT53AmxG+E0VjFny5myGRxXwz7Khj4+Xb24FgMruhBG1HA/uBZ57y 4hTvSv+Rjat4hWQ0JCly6ancvRUCdy2FWR6qu4vZrDYjsf2ubV8p9Hl/1lw7rUYf cmRQt4cMmEsiaLce3fZrTzyIw4is6lgak6bkyR4CC70JL1fk+iA= =Cht4 -----END PGP SIGNATURE-----