fce7287656
Fixes the following vulnerabilities: CVE-2025-11187 - Improper validation of PBMAC1 parameters in PKCS#12 MAC verification. CVE-2025-15467 - Stack buffer overflow in CMS AuthEnvelopedData parsing. CVE-2025-15468 - NULL dereference in SSL_CIPHER_find() function on unknown cipher ID. CVE-2025-15469 - ‘openssl dgst’ one-shot codepath silently truncates inputs >16MB. CVE-2025-66199 - TLS 1.3 CompressedCertificate excessive memory allocation. CVE-2025-68160 - Heap out-of-bounds write in BIO_f_linebuffer on short writes. CVE-2025-69418 - Unauthenticated/unencrypted trailing bytes with low-level OCB function calls CVE-2025-69419 - Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion. CVE-2025-69420 - Missing ASN1_TYPE validation in TS_RESP_verify_response() function. CVE-2025-69421 - NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function CVE-2026-22795 - Missing ASN1_TYPE validation in PKCS#12 parsing CVE-2026-22796 - ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function For more details, see the announcement: https://openssl-library.org/post/2026-01-27-release-announcement/ Drop now upstreamed 0004-Scope-aes_cfb128_vaes_encdec_wrapper-to-x64.patch: https://github.com/openssl/openssl/commit/f529d2659155883026cc5fe1e3a560c274da86b9 Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Julien Olivain <ju.o@free.fr>
6 lines
300 B
Plaintext
6 lines
300 B
Plaintext
# From https://github.com/openssl/openssl/releases/download/openssl-3.6.1/openssl-3.6.1.tar.gz.sha256
|
|
sha256 b1bfedcd5b289ff22aee87c9d600f515767ebf45f77168cb6d64f231f518a82e openssl-3.6.1.tar.gz
|
|
|
|
# License files
|
|
sha256 7d5450cb2d142651b8afa315b5f238efc805dad827d91ba367d8516bc9d49e7a LICENSE.txt
|