openwrt/package/libs/openssl/patches
Hauke Mehrtens 6e068b7052
Some checks are pending
Build all core packages / Build all core packages for selected target (push) Waiting to run
openssl: Update to version 3.0.18
OpenSSL 3.0.18 is a security patch release. The most severe CVE fixed in this
release is Moderate.

This release incorporates the following bug fixes and mitigations:

 * Fix Out-of-bounds read & write in RFC 3211 KEK Unwrap. (CVE-2025-9230)

 * Fix Out-of-bounds read in HTTP client no_proxy handling. (CVE-2025-9232)

The removed patch is included upstream:
c0d968f0ac

Link: https://github.com/openwrt/openwrt/pull/20312
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2025-10-13 23:41:16 +02:00
..
100-Configure-afalg-support.patch openssl: Update to version 3.0.17 2025-07-10 20:47:58 +02:00
110-openwrt_targets.patch openssl: add linux64-loongarch64 into the targets list 2024-05-04 14:14:24 +08:00
120-strip-cflags-from-binary.patch openssl: update to 3.0.12 2023-10-26 00:00:18 +02:00
130-dont-build-fuzz-docs.patch openssl: bump to 3.0.8 2023-02-20 11:24:17 +01:00
140-allow-prefer-chacha20.patch openssl: update to 3.0.13 2024-02-02 08:46:52 +03:00
150-openssl.cnf-add-engines-conf.patch openssl: add legacy provider 2023-04-05 08:24:49 -03:00
500-e_devcrypto-default-to-not-use-digests-in-engine.patch openssl: fix sysupgrade failure with devcrypto 2023-03-06 18:09:13 -03:00
510-e_devcrypto-ignore-error-when-closing-session.patch openssl: fix sysupgrade failure with devcrypto 2023-03-06 18:09:13 -03:00