-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 17:04:15 +0200 Source: nghttp2 Binary: libnghttp2-14 libnghttp2-14-dbgsym libnghttp2-dev nghttp2-client nghttp2-client-dbgsym nghttp2-proxy nghttp2-proxy-dbgsym nghttp2-server nghttp2-server-dbgsym Architecture: ppc64el Version: 1.64.0-1.1+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Lukas Märdian Description: libnghttp2-14 - library implementing HTTP/2 protocol (shared library) libnghttp2-dev - library implementing HTTP/2 protocol (development files) nghttp2-client - client implementing HTTP/2 protocol nghttp2-proxy - reverse proxy implementing HTTP/2 protocol nghttp2-server - server implementing HTTP/2 protocol Closes: 1131369 Changes: nghttp2 (1.64.0-1.1+deb13u1) trixie-security; urgency=medium . * Non-maintainer upload by the Security Team. * CVE-2026-27135 (Closes: #1131369) Fix missing iframe->state validations to avoid assertion failure. * Add test for CVE-2026-27135 (cherry-picked from upstream c619c7b) Checksums-Sha1: 49499673be003ff707e1628f854bdd3f88843ec0 237620 libnghttp2-14-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb 3bd5198e539c148ab5c5824baa3aa47888ea6238 82828 libnghttp2-14_1.64.0-1.1+deb13u1_ppc64el.deb 71d86492fd85a0a06eb50c25faf7ec9b038918b4 123956 libnghttp2-dev_1.64.0-1.1+deb13u1_ppc64el.deb 5532fdfb2bf7fb567705f16a72b45f78f7a8566f 2126276 nghttp2-client-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb bbc923f552e1e3eaf176d303a0d0219e7c368f1c 190084 nghttp2-client_1.64.0-1.1+deb13u1_ppc64el.deb c8debcf18b16d1080a50a281a12c88d7b8f4a28b 6299068 nghttp2-proxy-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb 1769df634ebc8b5ada7acdfcdbbd3a318531cf3f 436352 nghttp2-proxy_1.64.0-1.1+deb13u1_ppc64el.deb 5cac29807a1786a62c844c3a22a9cb60643d19f5 1152440 nghttp2-server-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb 823d6b13dc26937457782d12efd17d9735484ec0 114548 nghttp2-server_1.64.0-1.1+deb13u1_ppc64el.deb 1a7c048b66a8e78157c8a2da7024ce686fb41bad 8750 nghttp2_1.64.0-1.1+deb13u1_ppc64el-buildd.buildinfo Checksums-Sha256: d37cac949602a3999198fb72e14cf39dc7825598da3a6eb4652d0b53a28e1945 237620 libnghttp2-14-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb 3ef80bc9aa3061b86a535559eb3f96667483590e0ab1f3d300c27abf2015fd13 82828 libnghttp2-14_1.64.0-1.1+deb13u1_ppc64el.deb 4148671517e26153172d59c45b1038d666b374a24ee827c9e3452ab0a6abe84a 123956 libnghttp2-dev_1.64.0-1.1+deb13u1_ppc64el.deb 5c9d4f1707e4739e817f0e821ca8e99f3928073bf8a812071df431bec30c7fb0 2126276 nghttp2-client-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb 956d7018b602c889b7a28269d93f4e65866989a663d78511e74076bb76a514d3 190084 nghttp2-client_1.64.0-1.1+deb13u1_ppc64el.deb f6e29a6fb76d886dbde0821301c41d8cf195be4f731b965f59641cadb700168b 6299068 nghttp2-proxy-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb c5fda36be75b577ad386151f3ccd1514a1ab88f864a5c4413d4c748e9231aad7 436352 nghttp2-proxy_1.64.0-1.1+deb13u1_ppc64el.deb 095db0b2d302fa439fee80617c1ccb040201c5c84601fd14c303fb2fca36fd7f 1152440 nghttp2-server-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb 9c9f5ea16eb469815842f1d93443e16c7d67a1d83316ac787d4cc7a04d57f947 114548 nghttp2-server_1.64.0-1.1+deb13u1_ppc64el.deb 28a2c1564f4894b1ba2015876f09c7ffb5470518246c36736b08ebb6ffce2427 8750 nghttp2_1.64.0-1.1+deb13u1_ppc64el-buildd.buildinfo Files: edb1e51bbfcbea93c30c633ae0e3e207 237620 debug optional libnghttp2-14-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb b9242fcfcfe50568ae8ace215b674e3d 82828 libs optional libnghttp2-14_1.64.0-1.1+deb13u1_ppc64el.deb 4c01491ff069c07259587488dc3940c5 123956 libdevel optional libnghttp2-dev_1.64.0-1.1+deb13u1_ppc64el.deb 00ae0a6e07045bd10e0ad4399a378492 2126276 debug optional nghttp2-client-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb fe3248059e397788ed62018656366657 190084 httpd optional nghttp2-client_1.64.0-1.1+deb13u1_ppc64el.deb 2aa34f32237934555b40c11c12e0acdc 6299068 debug optional nghttp2-proxy-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb 169ee7a36ca216e9c24eb3b95097fc21 436352 httpd optional nghttp2-proxy_1.64.0-1.1+deb13u1_ppc64el.deb 48bebe9d3fc69e8a569c42a8ac8a6148 1152440 debug optional nghttp2-server-dbgsym_1.64.0-1.1+deb13u1_ppc64el.deb 6922c979dffbfbcd86d88272a5f65b1f 114548 httpd optional nghttp2-server_1.64.0-1.1+deb13u1_ppc64el.deb 385d6d245a10577a36bbcee838020fce 8750 httpd optional nghttp2_1.64.0-1.1+deb13u1_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmoEbqAACgkQ2FRWNm40 e2bPoxAAsiVjMqTj5ZGoWY0IBg8hw2QbgtOpm+R+5yR0aOyLURuEyvvmCisJ81QW b+yPW00y3qSE1hHCBgFlALk0Fn7sem/MdNTFVxtqD005XhsRKnJIMGNC1DR6ovIg UPOARjr9KJgYVUHv3epBeNPVb9dvvmK1Rw49BGoybkBZ3JftFcFkUAfD6rHeLj8G MpagFXFfvg9yASJt4mcR4/mrAfJH2txnN5s9zYS8Tn/7Ty/EgevxczZV77LrKguM o/vutrOQjPEKyMSHVBj5mzMrpjzvMb62yGY/mYk+BCHKr+ReNVISB1eu6YGn5Y6o og/y0O8oPVRXeVEahQW2IR0E23eQM0XYkTzveIUuPataUYWjlaO9jlkcOncaEBOA xeaDta8UPhU91rJeI5q3hBcA45Y6y6kCAux1LNZVQbte6ODLJ/6FRKfyUQ835xMr U4ylrdRHW04gu1/D0uNapS1c3KcAEkw2fiMkk6Lex2/ysOJ08Gcg2sJD1yMwq5L3 Ss3MoBltz8ul4EV2TObU/wezMS1qgUx2mwOevg6Jtoq/q8MeTvkQQx+1yjglCu2T zlXOXOpabeBbEo/LiX03N0EcdDhgbjEWCP6qd3dgk58LQMZuiPCvkecx6psU8RAl awSZQoi4jqf0Va8EzVPsQQX2gWt3UnqdUdtTYaYJCUicjr/gYFI= =VTsm -----END PGP SIGNATURE-----