openwrt/package
Hauke Mehrtens 158a33591d mbedtls: update to version 2.28.2
Changelog: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.2
This release of Mbed TLS provides bug fixes and minor enhancements. This
release includes fixes for security issues.

Fixes the following CVEs:
* CVE-2022-46393: Fix potential heap buffer overread and overwrite in
DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and
MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.

* CVE-2022-46392: An adversary with access to precise enough information
about memory accesses (typically, an untrusted operating system
attacking a secure enclave) could recover an RSA private key after
observing the victim performing a single private-key operation if the
window size used for the exponentiation was 3 or smaller.

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
(cherry picked from commit af3c9b74e1)
2022-12-31 14:45:23 +01:00
..
base-files base-files: support "metric" in board.json 2022-12-01 14:53:20 +01:00
boot sunxi: remove frequency for NanoPi R1 2022-12-22 00:45:24 +01:00
devel strace: replace PKG_CPE_ID 2022-11-07 12:29:08 +02:00
firmware kernel: kmod-net-rtl8192su: Remove package 2022-12-15 00:45:28 +01:00
kernel kernel: remove hack patch, move kirkwood specific kmods to target modules.mk 2022-12-27 08:05:23 +01:00
libs mbedtls: update to version 2.28.2 2022-12-31 14:45:23 +01:00
network uhttpd: update to latest Git HEAD 2022-12-26 17:20:47 +01:00
system rpcd: update to latest Git HEAD 2022-12-19 15:33:27 +01:00
utils e2fsprogs: Fix CVE-2022-1304 2022-12-06 23:29:14 +01:00
Makefile build: fix opkg install step for large package selection 2021-05-12 11:13:53 +02:00