openssl: Update to version 3.6.5
Commit Message
- Update from version 3.6.4 to 3.6.5
- Update of rootfile
- 13 CVE fixes
- Changelog
3.6.5
OpenSSL 3.6.5 is a security patch release. The most severe CVE fixed
in this release is High.
This release incorporates the following bug fixes and mitigations:
* Fixed DTLS retransmissions of handshake messages from a stale buffer offset.
([CVE-2026-84782])
* Fixed excessive memory allocation in relative CRLDP processing.
([CVE-2026-35189])
* Fixed QUIC unvalidated amplification credit may be over-accounted.
([CVE-2026-35191])
* Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC.
([CVE-2026-42772])
* Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves.
([CVE-2026-54872])
* Fixed QUIC `STREAM` fragment metadata DoS.
([CVE-2026-54873])
* Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V.
([CVE-2026-54875])
* Fixed out-of-bounds access after `SSL_set_SSL_CTX()` during a handshake.
([CVE-2026-72897])
* Fixed QUIC connection-level flow control was not enforced for streams.
([CVE-2026-75804])
* Fixed a NULL pointer dereference in CMP client revocation response handling.
([CVE-2026-75805])
* Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS.
([CVE-2026-75806])
* Fixed a timing side-channel in SM2 signature generation.
([CVE-2026-77696])
* Fixed an unbounded `RETIRE_CONNECTION_ID` backlog in QUIC stack
implementation.
([CVE-2026-84784])
* Fixed a bug where `EVP_DecryptFinal()` incorrectly reported a stale success
on AES-SIV authentication failure.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/openssl | 3 +++
lfs/openssl | 4 ++--
2 files changed, 5 insertions(+), 2 deletions(-)
@@ -850,6 +850,7 @@ usr/lib/ossl-modules/legacy.so
#usr/share/doc/openssl/html/man3/UI_UTIL_read_pw.html
#usr/share/doc/openssl/html/man3/UI_create_method.html
#usr/share/doc/openssl/html/man3/UI_new.html
+#usr/share/doc/openssl/html/man3/X509V3_EXT_nconf_nid.html
#usr/share/doc/openssl/html/man3/X509V3_EXT_print.html
#usr/share/doc/openssl/html/man3/X509V3_get_d2i.html
#usr/share/doc/openssl/html/man3/X509V3_set_ctx.html
@@ -6239,6 +6240,8 @@ usr/lib/ossl-modules/legacy.so
#usr/share/man/man3/USERNOTICE_new.3ossl
#usr/share/man/man3/X509V3_EXT_d2i.3ossl
#usr/share/man/man3/X509V3_EXT_i2d.3ossl
+#usr/share/man/man3/X509V3_EXT_nconf.3ossl
+#usr/share/man/man3/X509V3_EXT_nconf_nid.3ossl
#usr/share/man/man3/X509V3_EXT_print.3ossl
#usr/share/man/man3/X509V3_EXT_print_fp.3ossl
#usr/share/man/man3/X509V3_add1_i2d.3ossl
@@ -24,7 +24,7 @@
include Config
-VER = 3.6.4
+VER = 3.6.5
THISAPP = openssl-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -72,7 +72,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 93d5fcd284a52963b476f98e9915359a1025a9487cb2d15d7437e9b9a8058050ae249f0b76b5627f589036cecda62c69aebfab6c8be2ddcf82ae7e3a6ff87804
+$(DL_FILE)_BLAKE2 = 99dc542e433c8eceee43a437656907dc9fda41bf0209453b11f3d2f4c193e961fd05bfa38c53ad9863843eb68eac1f76380b2879ca20ccb0197ff815599659b7
install : $(TARGET)