From patchwork Thu Oct 1 15:55:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10292 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hwc2D64WXz3wh3 for ; Thu, 01 Oct 2026 15:55:32 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hwc2D193Zz5cP for ; Thu, 01 Oct 2026 15:55:32 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hwc2D0PVyz2xYb for ; Thu, 01 Oct 2026 15:55:32 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hwc293Zd5z2xHd for ; Thu, 01 Oct 2026 15:55:29 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hwc281d85z6M; Thu, 01 Oct 2026 15:55:28 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1790870128; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=eKOOHgbfWMVVxmVFSoAtQLil4nOHQYJsXwi+g9iV7jE=; b=o5NKCxFSd6MRvlawzkOUW/JehxCe20vh1S+30hz+WNZUzfp7rVNFgSA7cF26gmiATjBQVs Ff+Td2UR7DnCUzBw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1790870128; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=eKOOHgbfWMVVxmVFSoAtQLil4nOHQYJsXwi+g9iV7jE=; b=Gq8zhQZpKsH35MPLFz7QtX1+ae/VkmV4N74o5jpWqgjfpOaLdMRDIKMb8RfcmQbv4VPVgF 658ib8lC+pJWKCzCYQ7B6xZCgRTsqYXK17a/QhmYQ7h2DRREwL6A4NmjmKEp2MffxWKU3T NGEUQr0uzkWMVhtwBQVwGDMR5l6KXTSZw7gtAhARAhOR2pZOVegs1o/sQYXCrfBeWzjiOP AgCSYYk62tyFnbAAmgiOeF6WR+RGRrRnrgpwLkAsQ/CpS4I+E/ZvhYVKS5sHW+5TY3fCX7 PIxO/7sF+2BLcFdkRrwDNYHuemk6Vf5/RedBgBDIOMf3Km5kUfPJNm8M2ny7rg== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] openssl: Update to version 3.6.5 Date: Thu, 1 Oct 2026 17:55:25 +0200 Message-ID: <20261001155525.2514601-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 3.6.4 to 3.6.5 - Update of rootfile - 13 CVE fixes - Changelog 3.6.5 OpenSSL 3.6.5 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: * Fixed DTLS retransmissions of handshake messages from a stale buffer offset. ([CVE-2026-84782]) * Fixed excessive memory allocation in relative CRLDP processing. ([CVE-2026-35189]) * Fixed QUIC unvalidated amplification credit may be over-accounted. ([CVE-2026-35191]) * Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. ([CVE-2026-42772]) * Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. ([CVE-2026-54872]) * Fixed QUIC `STREAM` fragment metadata DoS. ([CVE-2026-54873]) * Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. ([CVE-2026-54875]) * Fixed out-of-bounds access after `SSL_set_SSL_CTX()` during a handshake. ([CVE-2026-72897]) * Fixed QUIC connection-level flow control was not enforced for streams. ([CVE-2026-75804]) * Fixed a NULL pointer dereference in CMP client revocation response handling. ([CVE-2026-75805]) * Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. ([CVE-2026-75806]) * Fixed a timing side-channel in SM2 signature generation. ([CVE-2026-77696]) * Fixed an unbounded `RETIRE_CONNECTION_ID` backlog in QUIC stack implementation. ([CVE-2026-84784]) * Fixed a bug where `EVP_DecryptFinal()` incorrectly reported a stale success on AES-SIV authentication failure. Signed-off-by: Adolf Belka --- config/rootfiles/common/openssl | 3 +++ lfs/openssl | 4 ++-- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/config/rootfiles/common/openssl b/config/rootfiles/common/openssl index cda9b5571..5b0aa5ad5 100644 --- a/config/rootfiles/common/openssl +++ b/config/rootfiles/common/openssl @@ -850,6 +850,7 @@ usr/lib/ossl-modules/legacy.so #usr/share/doc/openssl/html/man3/UI_UTIL_read_pw.html #usr/share/doc/openssl/html/man3/UI_create_method.html #usr/share/doc/openssl/html/man3/UI_new.html +#usr/share/doc/openssl/html/man3/X509V3_EXT_nconf_nid.html #usr/share/doc/openssl/html/man3/X509V3_EXT_print.html #usr/share/doc/openssl/html/man3/X509V3_get_d2i.html #usr/share/doc/openssl/html/man3/X509V3_set_ctx.html @@ -6239,6 +6240,8 @@ usr/lib/ossl-modules/legacy.so #usr/share/man/man3/USERNOTICE_new.3ossl #usr/share/man/man3/X509V3_EXT_d2i.3ossl #usr/share/man/man3/X509V3_EXT_i2d.3ossl +#usr/share/man/man3/X509V3_EXT_nconf.3ossl +#usr/share/man/man3/X509V3_EXT_nconf_nid.3ossl #usr/share/man/man3/X509V3_EXT_print.3ossl #usr/share/man/man3/X509V3_EXT_print_fp.3ossl #usr/share/man/man3/X509V3_add1_i2d.3ossl diff --git a/lfs/openssl b/lfs/openssl index 3eb2c85b5..fe8c33d2a 100644 --- a/lfs/openssl +++ b/lfs/openssl @@ -24,7 +24,7 @@ include Config -VER = 3.6.4 +VER = 3.6.5 THISAPP = openssl-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -72,7 +72,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 93d5fcd284a52963b476f98e9915359a1025a9487cb2d15d7437e9b9a8058050ae249f0b76b5627f589036cecda62c69aebfab6c8be2ddcf82ae7e3a6ff87804 +$(DL_FILE)_BLAKE2 = 99dc542e433c8eceee43a437656907dc9fda41bf0209453b11f3d2f4c193e961fd05bfa38c53ad9863843eb68eac1f76380b2879ca20ccb0197ff815599659b7 install : $(TARGET)