]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
openssl: Upgrade 1.1.1t -> 1.1.1v
authorPeter Marko <peter.marko@siemens.com>
Thu, 10 Aug 2023 17:46:12 +0000 (19:46 +0200)
committerSteve Sakoman <steve@sakoman.com>
Sat, 12 Aug 2023 15:38:11 +0000 (05:38 -1000)
commitbe5d49d86553769deaf4754969d2cf6931d6ac34
tree5ad22c16926b901cdee348a8614733f1c6f837e3
parent9d509daf5fdae6b5dd8a81490ee40ea119a42024
openssl: Upgrade 1.1.1t -> 1.1.1v

https://www.openssl.org/news/openssl-1.1.1-notes.html
Major changes between OpenSSL 1.1.1u and OpenSSL 1.1.1v [1 Aug 2023]
* Fix excessive time spent checking DH q parameter value (CVE-2023-3817)
* Fix DH_check() excessive time with over sized modulus (CVE-2023-3446)
Major changes between OpenSSL 1.1.1t and OpenSSL 1.1.1u [30 May 2023]
* Mitigate for very slow `OBJ_obj2txt()` performance with gigantic OBJECT IDENTIFIER sub-identities. (CVE-2023-2650)
* Fixed documentation of X509_VERIFY_PARAM_add0_policy() (CVE-2023-0466)
* Fixed handling of invalid certificate policies in leaf certificates (CVE-2023-0465)
* Limited the number of nodes created in a policy tree ([CVE-2023-0464])

All CVEs for upgrade to 1.1.1u were already patched, so effectively
this will apply patches for CVE-2023-3446 and CVE-2023-3817 plus
several non-CVE fixes.

Because of mips build changes were backported to openssl 1.1.1 branch,
backport of a patch from kirkstone is necessary.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-connectivity/openssl/openssl/0001-Configure-do-not-tweak-mips-cflags.patch [new file with mode: 0644]
meta/recipes-connectivity/openssl/openssl/CVE-2023-0464.patch [deleted file]
meta/recipes-connectivity/openssl/openssl/CVE-2023-0465.patch [deleted file]
meta/recipes-connectivity/openssl/openssl/CVE-2023-0466.patch [deleted file]
meta/recipes-connectivity/openssl/openssl/CVE-2023-2650.patch [deleted file]
meta/recipes-connectivity/openssl/openssl_1.1.1v.bb [moved from meta/recipes-connectivity/openssl/openssl_1.1.1t.bb with 96% similarity]