Re: [LFS Trac] #5793: openssl-3.5.4 (was: openssl-3.5.3)

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5793: openssl-3.5.4
-------------------------+-----------------------
 Reporter:  Bruce Dubbs  |       Owner:  lfs-book
     Type:  enhancement  |      Status:  closed
 Priority:  high         |   Milestone:  12.5
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:  fixed
 Keywords:               |
-------------------------+-----------------------
Changes (by Douglas R. Reno):

 * priority:  normal => high
 * summary:  openssl-3.5.3 => openssl-3.5.4

Comment:

 {{{
 Changes and CVEs fixed in 3.5.4:

     CVE-2025-9230 - Fix Out-of-bounds read & write in RFC 3211 KEK Unwrap.
     CVE-2025-9231 - Fix Timing side-channel in SM2 algorithm on 64-bit
 ARM.
     CVE-2025-9232 - Fix Out-of-bounds read in HTTP client no_proxy
 handling.
     Reverted the synthesised OPENSSL_VERSION_NUMBER change for the release
 builds, as it
 broke some existing applications that relied on the previous 3.x
 semantics, as
 documented in OpenSSL_version(3).
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5793#comment:4>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.