CVS: cvs.openbsd.org: ports

Theo Buehler <[email protected]> Wed, 5 Aug 2026 10:36:29 -0600 (MDT)
Newsgroups gmane.os.openbsd.ports.cvs
Message-ID <[email protected]>
CVSROOT:	/cvs
Module name:	ports
Changes by:	[email protected]	2026/08/05 10:36:29

Modified files:
	security/openssl/4.0: Makefile 
Added files:
	security/openssl/4.0/patches: patch-crypto_x509_x509_vfy_c 

Log message:
openssl/4.0: plug client-side memleak

Free bs when the OCSP basic response contains no single responses.

I have no idea why this utterly trivial change needed almost as many lines
of explanatory comment as it took weeks to merge it, plus a CVE on top, but
here we are. My time's already been wasted...

Free BS indeed: https://www.openwall.com/lists/oss-security/2026/08/05/8