MFV: crypto/openssl: update to 3.5.6This change brings in version 3.5.6 of OpenSSL, which featuresseveral security fixes (the highest of which is a MEDIUM severityissue), as well as some miscella
MFV: crypto/openssl: update to 3.5.6This change brings in version 3.5.6 of OpenSSL, which featuresseveral security fixes (the highest of which is a MEDIUM severityissue), as well as some miscellaneous feature updates.Please see the release notes [1] for more details.PS Apologies for the confusing merge commits -- I was testing out anew automated update process and failed to catch the commit messageissues until after I pushed the change.1. https://github.com/openssl/openssl/blob/openssl-3.5.6/NEWS.mdMFC after: 1 day (the security issues warrant a quick backport).Merge commit 'ab5fc4ac933ff67bc800e774dffce15e2a541e90'
show more ...
OpenSSL: Vendor import of OpenSSL 3.0.13 * Fixed PKCS12 Decoding crashes ([CVE-2024-0727]) * Fixed Excessive time spent checking invalid RSA public keys ([CVE-2023-6237]) * Fixed POLY1305 MAC
OpenSSL: Vendor import of OpenSSL 3.0.13 * Fixed PKCS12 Decoding crashes ([CVE-2024-0727]) * Fixed Excessive time spent checking invalid RSA public keys ([CVE-2023-6237]) * Fixed POLY1305 MAC implementation corrupting vector registers on PowerPC CPUs which support PowerISA 2.07 ([CVE-2023-6129]) * Fix excessive time spent in DH check / generation with large Q parameter value ([CVE-2023-5678])Release notes can be found at https://www.openssl.org/news/openssl-3.0-notes.html.Approved by: emasteMFC after: 3 daysMerge commit '9dd13e84fa8eca8f3462bd55485aa3da8c37f54a'