From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Wed, 08 Feb 2023 12:51:07 +0100 Received: from metis.ext.pengutronix.de ([2001:67c:670:201:290:27ff:fe1d:cc33]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1pPiyj-000W5u-FT for lore@lore.pengutronix.de; Wed, 08 Feb 2023 12:51:07 +0100 Received: from localhost ([127.0.0.1] helo=metis.ext.pengutronix.de) by metis.ext.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1pPiyg-0005D1-H5; Wed, 08 Feb 2023 12:51:06 +0100 Received: from drehscheibe.grey.stw.pengutronix.de ([2a0a:edc0:0:c01:1d::a2]) by metis.ext.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1pPixl-0001Mw-44; Wed, 08 Feb 2023 12:50:09 +0100 Received: from [2a0a:edc0:0:1101:1d::54] (helo=dude05.red.stw.pengutronix.de) by drehscheibe.grey.stw.pengutronix.de with esmtp (Exim 4.94.2) (envelope-from ) id 1pPixi-003VOM-Qz; Wed, 08 Feb 2023 12:50:08 +0100 Received: from mol by dude05.red.stw.pengutronix.de with local (Exim 4.94.2) (envelope-from ) id 1pPixj-008RAK-7l; Wed, 08 Feb 2023 12:50:07 +0100 From: Michael Olbrich To: ptxdist@pengutronix.de Date: Wed, 8 Feb 2023 12:50:07 +0100 Message-Id: <20230208115007.2011005-1-m.olbrich@pengutronix.de> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20230208080107.2504460-1-christian.melki@t2data.com> References: <20230208080107.2504460-1-christian.melki@t2data.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: Re: [ptxdist] [APPLIED] openssl: Version bump. 1.1.1s -> 1.1.1t. X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Cc: Christian Melki Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.ext.pengutronix.de); SAEximRunCond expanded to false Thanks, applied as 89f1032149d39b2f5ac41649f1441120b14891f3. Michael [sent from post-receive hook] On Wed, 08 Feb 2023 12:50:07 +0100, Christian Melki wrote: > Plug 4 CVEs. > https://www.openssl.org/news/cl111.txt > X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) > Use-after-free following BIO_new_NDEF (CVE-2023-0215) > Double free after calling PEM_read_bio_ex (CVE-2022-4450) > Timing Oracle in RSA Decryption (CVE-2022-4304) > > * Forward patchset. Applies cleanly. > > Signed-off-by: Christian Melki > Message-Id: <20230208080107.2504460-1-christian.melki@t2data.com> > Signed-off-by: Michael Olbrich > > diff --git a/patches/openssl-1.1.1s/0001-debian-targets.patch b/patches/openssl-1.1.1t/0001-debian-targets.patch > similarity index 100% > rename from patches/openssl-1.1.1s/0001-debian-targets.patch > rename to patches/openssl-1.1.1t/0001-debian-targets.patch > diff --git a/patches/openssl-1.1.1s/0002-pic.patch b/patches/openssl-1.1.1t/0002-pic.patch > similarity index 100% > rename from patches/openssl-1.1.1s/0002-pic.patch > rename to patches/openssl-1.1.1t/0002-pic.patch > diff --git a/patches/openssl-1.1.1s/0003-Set-systemwide-default-settings-for-libssl-users.patch b/patches/openssl-1.1.1t/0003-Set-systemwide-default-settings-for-libssl-users.patch > similarity index 100% > rename from patches/openssl-1.1.1s/0003-Set-systemwide-default-settings-for-libssl-users.patch > rename to patches/openssl-1.1.1t/0003-Set-systemwide-default-settings-for-libssl-users.patch > diff --git a/patches/openssl-1.1.1s/series b/patches/openssl-1.1.1t/series > similarity index 100% > rename from patches/openssl-1.1.1s/series > rename to patches/openssl-1.1.1t/series > diff --git a/rules/openssl.make b/rules/openssl.make > index 86f2e081c2f6..67600ab204ec 100644 > --- a/rules/openssl.make > +++ b/rules/openssl.make > @@ -17,9 +17,9 @@ PACKAGES-$(PTXCONF_OPENSSL) += openssl > # Paths and names > # > OPENSSL_BASE := 1.1.1 > -OPENSSL_BUGFIX := s > +OPENSSL_BUGFIX := t > OPENSSL_VERSION := $(OPENSSL_BASE)$(OPENSSL_BUGFIX) > -OPENSSL_MD5 := 077f69d357758c7d6ef686f813e16f30 > +OPENSSL_MD5 := 1cfee919e0eac6be62c88c5ae8bcd91e > OPENSSL := openssl-$(OPENSSL_VERSION) > OPENSSL_SUFFIX := tar.gz > OPENSSL_URL := \