+strongswan-5.8.4
+----------------
+
+- In IKEv1 Quick Mode make sure that a proposal exists before determining
+ lifetimes (fixes crash due to null pointer exception).
+
+- OpenSSL currently doesn't support squeezing bytes out of a SHAKE128/256
+ XOF (eXtended Output Function) multiple times. Unfortunately,
+ EVP_DigestFinalXOF() completely resets the context and later calls not
+ simply fail, they cause a null-pointer dereference in libcrypto. This
+ fixes the crash at the cost of repeating initializing the whole state
+ and allocating too much data for subsequent calls.
+
+
strongswan-5.8.3
----------------
# initialize & set some vars
# ============================
-AC_INIT([strongSwan],[5.8.3])
+AC_INIT([strongSwan],[5.8.4])
AM_INIT_AUTOMAKE(m4_esyscmd([
echo tar-ustar
echo subdir-objects
: ${TESTDIR=/srv/strongswan-testing}
# Kernel configuration
-: ${KERNELVERSION=5.5.11}
+: ${KERNELVERSION=5.5.13}
: ${KERNEL=linux-$KERNELVERSION}
: ${KERNELTARBALL=$KERNEL.tar.xz}
: ${KERNELCONFIG=$DIR/../config/kernel/config-5.5}
: ${KERNELPATCH=ha-5.0-abicompat.patch.bz2}
# strongSwan version used in tests
-: ${SWANVERSION=5.8.3}
+: ${SWANVERSION=5.8.4}
# Build directory where the guest kernel and images will be built
: ${BUILDDIR=$TESTDIR/build}