openwrt/package
Martin Schiller 9237dea49e openssl: update to version 3.0.19
OpenSSL 3.0.19 is a security patch release. The most severe CVE fixed
in this release is High.

This release incorporates the following bug fixes and mitigations:

 * Fixed Stack buffer overflow in CMS AuthEnvelopedData parsing.
   (CVE-2025-15467)

 * Fixed Heap out-of-bounds write in BIO_f_linebuffer on short writes.
   (CVE-2025-68160)

 * Fixed Unauthenticated/unencrypted trailing bytes with low-level OCB
   function calls. (CVE-2025-69418)

 * Fixed Out of bounds write in PKCS12_get_friendlyname() UTF-8
   conversion. (CVE-2025-69419)

 * Fixed Missing ASN1_TYPE validation in TS_RESP_verify_response()
   function. (CVE-2025-69420)

 * Fixed NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex()
   function. (CVE-2025-69421)

 * Fixed Missing ASN1_TYPE validation in PKCS#12 parsing.
   (CVE-2026-22795)

 * Fixed ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes()
   function. (CVE-2026-22796)

Signed-off-by: Martin Schiller <ms@dev.tdt.de>
Link: https://github.com/openwrt/openwrt/pull/21831
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2026-02-04 23:57:41 +01:00
..
base-files OpenWrt v24.10.5: revert to branch defaults 2025-12-18 21:39:37 +01:00
boot uboot-mediatek: fix build with swig 4.3.0 2026-01-19 01:18:44 +01:00
devel perf: disable slang support 2025-06-17 23:36:56 +02:00
firmware wireless-regdb: Update to version 2025.10.07 2025-12-17 22:08:20 +01:00
kernel mac80211: ath9k: Add RX inactivity detection and reset chip 2026-01-19 01:16:27 +01:00
libs openssl: update to version 3.0.19 2026-02-04 23:57:41 +01:00
network dropbear: backport security fixes 2025-12-17 21:19:28 +01:00
system ubus: update to Git HEAD (2025-10-17) 2025-10-18 14:56:36 +02:00
utils busybox: fix login applet on selinux 2025-07-27 19:42:04 +02:00
Makefile package: rework contents of package index.json 2025-06-11 19:12:09 +02:00