Home / mailings [SECURITY] [DSA 6412-1] botan3 security update
Posted on 05 August 2026
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6412-1 security@debian.org
https://www.debian.org/security/ Aron Xu
August 05, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : botan3
CVE ID : CVE-2026-44378
Debian Bug :
Multiple security issues were discovered in Botan, a C++ cryptography
library, which could result in denial of service, certificate validation
bypass or authentication bypass.
These issues have been addressed by updating botan3 to the new upstream
release 3.12.0. As a consequence this update changes the SONAME of the
shared library, and the runtime library package is renamed from
libbotan-3-7 to libbotan-3-12. No package in the stable distribution links
against the library, so no other packages in trixie are affected by this
change.
The libbotan-3-7 package is no longer built and will not be removed
automatically on upgrade if it had been installed manually. Locally built
or third-party software linking against libbotan-3-7 needs to be rebuilt
against libbotan-3-12, after which the old library package can be removed.
For the stable distribution (trixie), this problem has been fixed in
version 3.12.0+dfsg-2~deb13u1.
We recommend that you upgrade your botan3 packages.
For the detailed security status of botan3 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/botan3
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
