openssl: package the new bugfix release 3.0.2

Bug #1965141 reported by Simon Chopin
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openssl (Ubuntu)
Fix Released
Undecided
Thomas Ward

Bug Description

The latest bugfix release of the 3.0 branch is out, we should package it for Jammy.

In the preliminary packaging I've done the test suite fails, i'm trying to track down the cause ATM.

Tags: fr-2110

CVE References

Simon Chopin (schopin)
tags: added: fr-2110
Revision history for this message
Simon Chopin (schopin) wrote :

Attached is the debdiff for the upgrade. You can also find the package at https://launchpad.net/~schopin/+archive/ubuntu/test-ppa/+sourcepub/13390252/+listing-archive-extra (mind the version number).

Note the new Ubuntu-specific patch to disable some tests that use a configuration that's invalid under our changes (TLS 1.1 + seclevel 3).

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

This update will fix CVE-2022-0778, so the security team is interested in seeing it in jammy.

Revision history for this message
Thomas Ward (teward) wrote :

I've got some extra cycles later today, so I'll happily help the Security team out and get this uploaded later today (Eastern US time for clarity sake when I say "later today")

Changed in openssl (Ubuntu):
assignee: nobody → Thomas Ward (teward)
status: New → In Progress
Revision history for this message
Thomas Ward (teward) wrote :

[ubuntu/jammy-proposed] openssl 3.0.2-0ubuntu1 (Accepted)

Uploaded to proposed, it has to go through the usual process of passing autopkgtests and such. It shouldn't need any additional package rebuilds because of no ABI changes but expect autopkgtests to run hot a while

Changed in openssl (Ubuntu):
status: In Progress → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package openssl - 3.0.2-0ubuntu1

---------------
openssl (3.0.2-0ubuntu1) jammy; urgency=medium

  * New upstream bugfix release (LP: #1965141)
  * d/p/skip_tls1.1_seclevel3_tests.patch: new Ubuntu-specific patch for the
    testsuite

 -- Simon Chopin <email address hidden> Wed, 16 Mar 2022 09:35:51 +0100

Changed in openssl (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.