From fb7efde7e7c77ba516a637ec25aac486fadc6556181f1fa40e2926d06ee396a6 Mon Sep 17 00:00:00 2001 From: Robert Frohl Date: Wed, 26 Nov 2025 15:27:41 +0100 Subject: [PATCH] Update submodules from pool/rnp#1 and create patchinfo.20251126142654688873.93181000773252/_patchinfo --- .../_patchinfo | 18 ++++++++++++++++++ rnp | 2 +- 2 files changed, 19 insertions(+), 1 deletion(-) create mode 100644 patchinfo.20251126142654688873.93181000773252/_patchinfo diff --git a/patchinfo.20251126142654688873.93181000773252/_patchinfo b/patchinfo.20251126142654688873.93181000773252/_patchinfo new file mode 100644 index 0000000..68bea1e --- /dev/null +++ b/patchinfo.20251126142654688873.93181000773252/_patchinfo @@ -0,0 +1,18 @@ + + VUL-0: CVE-2025-13470,CVE-2025-13402: rnp: rnp PKESK session keys generated as all‑zero + cve#2025-13470 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-13470 + cve#2025-13402 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-13402 + AndreasStieger + moderate + security + Security update for rnp + This update for rnp fixes the following issues: + +- update to 0.18.1: + * CVE-2025-13470: PKESK (public-key encrypted) session keys were + generated as all-zero, allowing trivial decryption of messages + encrypted with public keys only (boo#1253957, CVE-2025-13402) + + rnp + + diff --git a/rnp b/rnp index 653d18b..b790fd4 160000 --- a/rnp +++ b/rnp @@ -1 +1 @@ -Subproject commit 653d18b13fca740e0048a62b59edb56a475c8f092232af6828ab1db2127a5547 +Subproject commit b790fd4c71565df00b11fecda9fd03693fadeb09af0b32ba647d016ea9c07b0a -- 2.51.1