<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src/crypto/err, branch vendor/openssl-3.5</title>
<subtitle>FreeBSD source tree</subtitle>
<id>https://cgit-dev.freebsd.org/src/atom?h=vendor%2Fopenssl-3.5</id>
<link rel='self' href='https://cgit-dev.freebsd.org/src/atom?h=vendor%2Fopenssl-3.5'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/'/>
<updated>2026-04-07T22:35:35Z</updated>
<entry>
<title>OpenSSL: import 3.5.6</title>
<updated>2026-04-07T22:35:35Z</updated>
<author>
<name>Enji Cooper</name>
<email>ngie@FreeBSD.org</email>
</author>
<published>2026-04-07T22:35:35Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=ab5fc4ac933ff67bc800e774dffce15e2a541e90'/>
<id>urn:sha1:ab5fc4ac933ff67bc800e774dffce15e2a541e90</id>
<content type='text'>
This change adds OpenSSL 3.5.6 from upstream [1].

The 3.5.5 artifact was been verified via PGP key [2] and by SHA256 checksum [3].

This is a security release, but also contains several bugfixes.

More information about the release (from a high level) can be found in
the release notes [4].

1. openssl-3.5.6.tar.gz
2. openssl-3.5.6.tar.gz.asc
3. openssl-3.5.6.tar.gz.sha256
4. https://github.com/openssl/openssl/blob/openssl-3.5.6/NEWS.md
</content>
</entry>
<entry>
<title>openssl: import 3.5.5</title>
<updated>2026-01-29T01:27:53Z</updated>
<author>
<name>Enji Cooper</name>
<email>ngie@FreeBSD.org</email>
</author>
<published>2026-01-29T01:27:53Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=808413da28df9fb93e1f304e6016b15e660f54c8'/>
<id>urn:sha1:808413da28df9fb93e1f304e6016b15e660f54c8</id>
<content type='text'>
This change adds OpenSSL 3.5.5 from upstream [1].

The 3.5.5 artifact was been verified via PGP key [2] and by SHA256 checksum [3].

This is a security release, but also contains several bugfixes.

More information about the release (from a high level) can be found in
the release notes [4].

1. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz
2. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz.asc
3. https://github.com/openssl/openssl/releases/download/openssl-3.5.5/openssl-3.5.5.tar.gz.sha256
4. https://github.com/openssl/openssl/blob/openssl-3.5.5/NEWS.md
</content>
</entry>
<entry>
<title>openssl: import 3.5.3</title>
<updated>2025-09-16T23:42:52Z</updated>
<author>
<name>Enji Cooper</name>
<email>ngie@FreeBSD.org</email>
</author>
<published>2025-09-16T23:42:52Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=aed904c48f330dc76da942a8ee2d6eef9d11f572'/>
<id>urn:sha1:aed904c48f330dc76da942a8ee2d6eef9d11f572</id>
<content type='text'>
This change adds OpenSSL 3.5.3 from upstream [1].

The 3.5.3 artifact was been verified via PGP key [2] and by SHA256 checksum [3].

This is a minor release with a single major bugfix to multithreading
support with `OSSL_STORE_CTX`.

More information about the release (from a high level) can be found in
the release notes [4].

1. https://github.com/openssl/openssl/releases/download/openssl-3.5.3/openssl-3.5.3.tar.gz
2. https://github.com/openssl/openssl/releases/download/openssl-3.5.3/openssl-3.5.3.tar.gz.asc
3. https://github.com/openssl/openssl/releases/download/openssl-3.5.3/openssl-3.5.3.tar.gz.sha256
4. https://github.com/openssl/openssl/blob/openssl-3.5.3/NEWS.md
</content>
</entry>
<entry>
<title>openssl: import 3.5.1</title>
<updated>2025-08-07T11:54:09Z</updated>
<author>
<name>Pierre Pronchery</name>
<email>khorben@FreeBSD.org</email>
</author>
<published>2025-07-11T21:17:50Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=1095efe41feed8ea5a6fe5ca123c347ae0914801'/>
<id>urn:sha1:1095efe41feed8ea5a6fe5ca123c347ae0914801</id>
<content type='text'>
This change adds OpenSSL 3.5.1 from upstream [1].

The 3.5.1 artifact was been verified via PGP key [2] and by SHA256 checksum [3].

More information about the release (from a high level) can be found in
the release notes [4].

1. https://github.com/openssl/openssl/releases/download/openssl-3.5.1/openssl-3.5.1.tar.gz
2. https://github.com/openssl/openssl/releases/download/openssl-3.5.1/openssl-3.5.1.tar.gz.asc
3. https://github.com/openssl/openssl/releases/download/openssl-3.5.1/openssl-3.5.1.tar.gz.sha256
4. https://github.com/openssl/openssl/blob/openssl-3.5.1/NEWS.md

Reviewed by:	ngie, philip
Approved by:	philip (mentor)
Sponsored by:	The FreeBSD Foundation
</content>
</entry>
<entry>
<title>openssl: import missing files from 3.5.0</title>
<updated>2025-08-07T11:53:44Z</updated>
<author>
<name>Pierre Pronchery</name>
<email>khorben@FreeBSD.org</email>
</author>
<published>2025-06-27T21:41:09Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=09a25192275b21412a51e3a2d5d6ff0eb147425d'/>
<id>urn:sha1:09a25192275b21412a51e3a2d5d6ff0eb147425d</id>
<content type='text'>
This change completes the import of OpenSSL 3.5.0 from upstream.

The source archive has been verified via PGP and SHA256:

1. https://github.com/openssl/openssl/releases/download/openssl-3.5.0/openssl-3.5.0.tar.gz
2. https://github.com/openssl/openssl/releases/download/openssl-3.5.0/openssl-3.5.0.tar.gz.asc
3. https://github.com/openssl/openssl/releases/download/openssl-3.5.0/openssl-3.5.0.tar.gz.sha256
4. https://github.com/openssl/openssl/blob/openssl-3.5.0/NEWS.md

Reviewed by:	ngie, philip
Approved by:	philip (mentor)
Sponsored by:	The FreeBSD Foundation
</content>
</entry>
<entry>
<title>openssl: import 3.5.0</title>
<updated>2025-05-07T22:37:22Z</updated>
<author>
<name>Enji Cooper</name>
<email>ngie@FreeBSD.org</email>
</author>
<published>2025-05-07T21:18:24Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=29536654cc41bf41b92dc836c47496dc6fe0b00c'/>
<id>urn:sha1:29536654cc41bf41b92dc836c47496dc6fe0b00c</id>
<content type='text'>
This change adds OpenSSL 3.5.0 from upstream [1].

The 3.5.0 artifact was been verified via PGP key [2] and by SHA256 checksum [3].

More information about the release (from a high level) can be found in
the release notes [4].

1. https://github.com/openssl/openssl/releases/download/openssl-3.5.0/openssl-3.5.0.tar.gz
2. https://github.com/openssl/openssl/releases/download/openssl-3.5.0/openssl-3.5.0.tar.gz.asc
3. https://github.com/openssl/openssl/releases/download/openssl-3.5.0/openssl-3.5.0.tar.gz.sha256
4. https://github.com/openssl/openssl/blob/openssl-3.5.0/NEWS.md
</content>
</entry>
<entry>
<title>openssl: Import OpenSSL 3.0.16</title>
<updated>2025-03-06T17:49:50Z</updated>
<author>
<name>Enji Cooper</name>
<email>ngie@FreeBSD.org</email>
</author>
<published>2025-03-06T17:49:50Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=1c34280346af8284acdc0eae39496811d37df25d'/>
<id>urn:sha1:1c34280346af8284acdc0eae39496811d37df25d</id>
<content type='text'>
This release incorporates the following bug fixes and mitigations:
- [CVE-2024-13176](https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176
- [CVE-2024-9143](https://www.openssl.org/news/vulnerabilities.html#CVE-2024-9143)

Release notes can be found at:
https://openssl-library.org/news/openssl-3.0-notes/index.html
</content>
</entry>
<entry>
<title>Import OpenSSL 3.0.14</title>
<updated>2024-06-20T23:24:17Z</updated>
<author>
<name>Enji Cooper</name>
<email>ngie@FreeBSD.org</email>
</author>
<published>2024-06-20T23:24:17Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=1070e7dca8223387baf5155524b28f62bfe7da3c'/>
<id>urn:sha1:1070e7dca8223387baf5155524b28f62bfe7da3c</id>
<content type='text'>
This release resolves 3 upstream found CVEs:
- Fixed potential use after free after SSL_free_buffers() is called (CVE-2024-4741)
- Fixed an issue where checking excessively long DSA keys or parameters may be very slow (CVE-2024-4603)
- Fixed unbounded memory growth with session handling in TLSv1.3 (CVE-2024-2511)
</content>
</entry>
<entry>
<title>OpenSSL: Vendor import of OpenSSL 3.0.13</title>
<updated>2024-02-02T09:48:38Z</updated>
<author>
<name>Cy Schubert</name>
<email>cy@FreeBSD.org</email>
</author>
<published>2024-02-02T04:39:16Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=9dd13e84fa8eca8f3462bd55485aa3da8c37f54a'/>
<id>urn:sha1:9dd13e84fa8eca8f3462bd55485aa3da8c37f54a</id>
<content type='text'>
* Fixed PKCS12 Decoding crashes ([CVE-2024-0727])
* Fixed Excessive time spent checking invalid RSA public keys
  ([CVE-2023-6237])
* Fixed POLY1305 MAC implementation corrupting vector registers on
  PowerPC CPUs which support PowerISA 2.07 ([CVE-2023-6129])
* Fix excessive time spent in DH check / generation with large Q
  parameter value ([CVE-2023-5678])

Release notes can be found at
	https://www.openssl.org/news/openssl-3.0-notes.html.
</content>
</entry>
<entry>
<title>OpenSSL: Vendor import of OpenSSL 3.0.12</title>
<updated>2023-10-24T17:48:36Z</updated>
<author>
<name>Ed Maste</name>
<email>emaste@FreeBSD.org</email>
</author>
<published>2023-10-24T17:45:46Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=825caf7e12445fa4818413cc37c8b45bebb6c3a9'/>
<id>urn:sha1:825caf7e12445fa4818413cc37c8b45bebb6c3a9</id>
<content type='text'>
 * Fix incorrect key and IV resizing issues when calling
   EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2()
   with OSSL_PARAM parameters that alter the key or IV length
   ([CVE-2023-5363]).

Sponsored by:	The FreeBSD Foundation
</content>
</entry>
</feed>
