openssl: import 3.5.5This change adds OpenSSL 3.5.5 from upstream [1].The 3.5.5 artifact was been verified via PGP key [2] and by SHA256 checksum [3].This is a security release, but also contai
openssl: import 3.5.5This change adds OpenSSL 3.5.5 from upstream [1].The 3.5.5 artifact was been verified via PGP key [2] and by SHA256 checksum [3].This is a security release, but also contains several bugfixes. All ofthe CVE-worthy issues have already been addressed on the targetbranch(es), so the net-result is that this is a bugfix release.More information about the release (from a high level) can be found inthe release notes [4].MFC after: 1 week1. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz2. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz.asc3. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz.sha2564. https://github.com/openssl/openssl/blob/openssl-3.5.5/NEWS.mdMerge commit '808413da28df9fb93e1f304e6016b15e660f54c8'
show more ...
crypto/openssl: update to 3.5.4This change includes all necessary changes required to update to OpenSSL3.5.4.More information about the 3.5.4 release can be found in the relevantrelease notes (
crypto/openssl: update to 3.5.4This change includes all necessary changes required to update to OpenSSL3.5.4.More information about the 3.5.4 release can be found in the relevantrelease notes (see 8e12a5c4eb3507846b5 for more details).Merge commit '8e12a5c4eb3507846b507d0afe87d115af41df40'
Merge commit '1095efe41feed8ea5a6fe5ca123c347ae0914801'Approved by: philip (mentor)Sponsored by: Alpha-Omega Beach Cleaning ProjectSponsored by: The FreeBSD Foundation
openssl: Import OpenSSL 3.0.16This release incorporates the following bug fixes and mitigations:- [CVE-2024-13176](https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176- [CVE-2024-9143
openssl: Import OpenSSL 3.0.16This release incorporates the following bug fixes and mitigations:- [CVE-2024-13176](https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176- [CVE-2024-9143](https://www.openssl.org/news/vulnerabilities.html#CVE-2024-9143)Release notes can be found at:https://openssl-library.org/news/openssl-3.0-notes/index.htmlMFC after: 1 weekDifferential Revision: https://reviews.freebsd.org/D49296
OpenSSL: Vendor import of OpenSSL 3.0.13 * Fixed PKCS12 Decoding crashes ([CVE-2024-0727]) * Fixed Excessive time spent checking invalid RSA public keys ([CVE-2023-6237]) * Fixed POLY1305 MAC
OpenSSL: Vendor import of OpenSSL 3.0.13 * Fixed PKCS12 Decoding crashes ([CVE-2024-0727]) * Fixed Excessive time spent checking invalid RSA public keys ([CVE-2023-6237]) * Fixed POLY1305 MAC implementation corrupting vector registers on PowerPC CPUs which support PowerISA 2.07 ([CVE-2023-6129]) * Fix excessive time spent in DH check / generation with large Q parameter value ([CVE-2023-5678])Release notes can be found at https://www.openssl.org/news/openssl-3.0-notes.html.Approved by: emasteMFC after: 3 daysMerge commit '9dd13e84fa8eca8f3462bd55485aa3da8c37f54a'