Skip to content

Commit 5bfa451

Browse files
deps: upgrade openssl sources to openssl-3.5.9
PR-URL: #66396 Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Filip Skokan <panva.ip@gmail.com> Reviewed-By: Juan José Arboleda <soyjuanarbol@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
1 parent 21090da commit 5bfa451

145 files changed

Lines changed: 4429 additions & 1368 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎deps/openssl/openssl/CHANGES.md‎

Lines changed: 304 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,296 @@ OpenSSL Releases
2828
OpenSSL 3.5
2929
-----------
3030

31+
### Changes between 3.5.8 and 3.5.9 [29 Sep 2026]
32+
33+
* Fixed DTLS retransmissions of handshake messages from a stale buffer offset.
34+
35+
Severity: High
36+
37+
Issue summary: The DTLS retransmission logic does not correctly handle
38+
a handshake message write that is suspended part-way through.
39+
The retransmitted message can be read past the message buffer
40+
and the retransmission overwrites the internal state the suspended write
41+
needs to resume correctly.
42+
43+
Impact summary: The retransmitted message can disclose a heap memory
44+
to the peer as plaintext handshake data or cause a crash and a Denial
45+
of Service when the read reaches an unmapped memory region.
46+
47+
Reported by: Laurent Gaffie (secorizon.com).
48+
49+
([CVE-2026-84782])
50+
51+
*Ryan Hooper*
52+
53+
* Fixed excessive memory allocation in relative CRLDP processing.
54+
55+
Severity: Low
56+
57+
Issue summary: A certificate with many `nameRelativeToCRLIssuer` CRL
58+
distribution points causes disproportionate heap growth when OpenSSL caches
59+
X.509 extensions.
60+
61+
Impact summary: Receiving a crafted certificate from a malicious peer
62+
can lead to significant memory pressure and possible Denial of Service
63+
in clients or in servers that solicit client certificates.
64+
65+
Reported by: Fuzz0x (ZKSC Institute of Security Research).
66+
67+
([CVE-2026-35189])
68+
69+
*Viktor Dukhovni*
70+
71+
* Fixed QUIC unvalidated amplification credit may be over-accounted.
72+
73+
Severity: Low
74+
75+
Issue summary: The OpenSSL QUIC server, when configured to not preform
76+
address validation, can be forced to count incoming packets multiple times
77+
in its unvalidated credit computation, leading to a violation
78+
of the [RFC 9000] unvalidated connection amplification limit of 3 times
79+
the amount of data received.
80+
81+
Impact summary: A remote attacker, who is able to spoof packets to a server
82+
using the OpenSSL QUIC implementation, might use the server
83+
for an amplification of a Distributed Denial of Service attack.
84+
85+
Reported by: Ali Firas and Nikolas Gauder (NVIDIA).
86+
87+
([CVE-2026-35191])
88+
89+
*Neil Horman*
90+
91+
* Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC.
92+
93+
Severity: Low
94+
95+
Issue summary: The QUIC stream reassembly algorithm performance deteriorates
96+
progressively as packets are arriving out of order. The worst case has
97+
a quadratic complexity, proportional to the number of stream frames kept
98+
in the buffer for the received stream data.
99+
100+
Impact summary: A remote QUIC peer that completes the handshake can create
101+
a connection-scoped CPU pressure and potentially a Denial of Service using
102+
compliant `STREAM` frames inside the advertised receive window, with low
103+
attacker bandwidth.
104+
105+
Reported by: Saku0512 and Opal Wright (Trail of Bits) in collaboration
106+
with OpenAI
107+
108+
([CVE-2026-42772])
109+
<!-- https://github.com/openssl/openssl/pull/32769 -->
110+
111+
*Alexandr Nedvědický*
112+
113+
* Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves.
114+
115+
Severity: Low
116+
117+
Issue summary: The generic elliptic-curve scalar multiplication, used
118+
for ECDSA and SM2 signature operations with curves that do not have
119+
a dedicated implementation, leaks information about the secret nonce
120+
through timing.
121+
122+
Impact summary: An attacker, who is able to measure signing times, may learn
123+
information about the per-signature secret nonce, which over many signatures
124+
can, via a Hidden Number Problem (lattice) attack, lead to recovery
125+
of the private key.
126+
127+
Reported by: Alicja Kario and George Pantelakis (Red Hat), based
128+
on the report of Youngjae Choi (Korea University).
129+
130+
([CVE-2026-54872])
131+
132+
*Igor Ustinov*
133+
134+
* Fixed QUIC `STREAM` fragment metadata DoS.
135+
136+
Severity: Low
137+
138+
Issue summary: QUIC process may keep memory for QUIC packet buffer
139+
for much longer period than necessary.
140+
141+
Impact summary: Remote peer can exploit this vulnerability by sending
142+
maliciously crafted packets, making the local QUIC stack to keep the memory
143+
for packet buffers allocated. The time for which the memory remains
144+
allocated is entirely under the control of the potentially malicious remote
145+
peer.
146+
147+
Reported by: Zhen Yan (AntAISecurityLab) and Bhabani Sankar Das.
148+
149+
([CVE-2026-54873])
150+
<!-- https://github.com/openssl/openssl/pull/32769 -->
151+
152+
*Alexandr Nedvědický*
153+
154+
* Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V.
155+
156+
Severity: Low
157+
158+
Issue summary: A non-constant-time optimized implementation of scalar
159+
point multiplication is used for SM2 private key operations on ARM64
160+
and RISC-V platforms.
161+
162+
Impact summary: An attacker able to measure the time taken by, or to observe
163+
the cache-line access pattern of, SM2 signing or decryption on an affected
164+
platform can learn information about the secret scalar.
165+
166+
Reported by: Abhinav Agarwal and Feng Xue.
167+
168+
([CVE-2026-54875])
169+
170+
*Igor Ustinov*
171+
172+
* Fixed out-of-bounds access after `SSL_set_SSL_CTX()` during a handshake.
173+
174+
Severity: Low
175+
176+
Issue summary: A TLS server that calls `SSL_set_SSL_CTX()` to switch
177+
a connection to a different `SSL_CTX` part way through a handshake may access
178+
memory beyond the end of an internal array if the replacement context knows
179+
about more provider signature algorithms than the context the connection was
180+
created from. Applications that never call `SSL_set_SSL_CTX()`
181+
are not affected.
182+
183+
Impact summary: A remote peer may be able to cause a small out-of-bounds
184+
read, and, in some circumstances, a fixed-value out-of-bounds write,
185+
on the server heap. This may lead to a Denial of Service.
186+
187+
Reported by: Filipe Casal (Trail of Bits) in collaboration with OpenAI,
188+
Brandon Luo, Luigino Camastra (Aisle Research), and Bhargava Shastry.
189+
190+
([CVE-2026-72897])
191+
192+
*Matt Caswell*
193+
194+
* Fixed QUIC connection-level flow control was not enforced for streams.
195+
196+
Severity: Low
197+
198+
Issue summary: OpenSSL QUIC stack does not enforce connection-level flow
199+
control for streams. Remote peers may send more bytes, as long as they fit
200+
within the stream flow control limits.
201+
202+
Impact summary: A malicious remote peer may exploit the lack of connection
203+
flow control for streams to make the QUIC stack receive ~100 MiB of memory
204+
instead of 768 KiB (default flow control window size).
205+
206+
Reportedby: Moltenbit, Bhabani Sankar Das, Saiyowa Security Team, mzfr.
207+
208+
([CVE-2026-75804])
209+
210+
*Alexandr Nedvědický*
211+
212+
* Fixed a NULL pointer dereference in CMP client revocation response handling.
213+
214+
Severity: Low
215+
216+
Issue summary: The OpenSSL Certificate Management Protocol (CMP) client
217+
that requests a certificate revocation on the basis of a PKCS#10 CSR may
218+
dereference a NULL pointer and terminate abnormally when processing a crafted
219+
revocation response.
220+
221+
Impact summary: The NULL pointer dereference happens on a read, which
222+
leads to a crash and a Denial of Service for the affected client application.
223+
224+
Reported by: Bhabani Sankar Das.
225+
226+
([CVE-2026-75805])
227+
228+
*Bhabani Sankar Das and Norbert Pócs*
229+
230+
* Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS.
231+
232+
Severity: Low
233+
234+
Issue summary: An established DTLS 1.2 association using an AEAD cipher suite
235+
can be terminated by a single unauthenticated datagram whose encrypted
236+
fragment is shorter than the mandatory explicit IV and authentication tag
237+
overhead.
238+
239+
Impact summary: An attacker who can send a datagram that is routed
240+
to an existing DTLS 1.2 association can tear that association down
241+
without knowing any key material. This is a Denial of Service, limited
242+
to the targeted association. There is no memory safety or confidentiality
243+
impact.
244+
245+
Reported by: Mounir IDRASSI.
246+
247+
([CVE-2026-75806])
248+
249+
*Mounir IDRASSI*
250+
251+
* Fixed a timing side-channel in SM2 signature generation.
252+
253+
Severity: Low
254+
255+
Issue summary: SM2 signature generation uses non-constant-time arithmetic
256+
on secret values, forming a timing side-channel.
257+
258+
Impact summary: An attacker able to measure SM2 signing times may learn
259+
information about the per-signature secret nonce, which over many signatures
260+
can, via a Hidden Number Problem (lattice) attack, lead to recovery
261+
of the private key.
262+
263+
Reported by: Vladimir Tokarev.
264+
265+
([CVE-2026-77696])
266+
267+
*Igor Ustinov and Viktor Dukhovni*
268+
269+
* Fixed an unbounded `RETIRE_CONNECTION_ID` backlog in QUIC stack
270+
implementation.
271+
272+
Severity: Low
273+
274+
Issue summary: A malicious remote peer may flood the local QUIC stack
275+
with `NEW_CONNECTION_ID` frames by avoiding a limit check on how many
276+
connection IDs the remote QUIC stack can use.
277+
278+
Impact summary: The local QUIC stack sends a `RETIRE_CONN_ID` frame
279+
for every `NEW_CONNECTION_ID` frame it receives. The `RETIRE_CONN_ID`
280+
frame is dispatched via the Control Frame Queue (CFQ). If the remote
281+
peer also withholds ACKs, then it can force the local stack to allocate
282+
up to ~400 MB (depending on ACK delay).
283+
284+
Reported by: Bhabani Sankar Das.
285+
286+
([CVE-2026-84784])
287+
288+
*Alexandr Nedvědický*
289+
290+
* Fixed a bug where `EVP_DecryptFinal()` incorrectly reported a stale success
291+
on AES-SIV authentication failure after a preciously successful message
292+
decryption.
293+
<!-- https://github.com/openssl/openssl/pull/31610 -->
294+
295+
*Abel Thomas*
296+
297+
* Fixed a bug in `OSSL_HTTP_get()` that allowed to perform HTTPS-to-HTTP
298+
downgrade through a relative redirect.
299+
<!-- https://github.com/openssl/openssl/pull/32694 -->
300+
301+
*Mounir IDRASSI*
302+
303+
* Changed the OpenSSL FIPS provider so that every algorithm advertised
304+
with `fips=yes` property explicitly exposes a `fips-indicator` gettable
305+
context parameter, that returns 1 for an approved operation. The absence
306+
of an indicator is no longer interpreted as approval. Algorithms advertised
307+
with `fips=no` property, including X448MLKEM1024, remain unapproved
308+
and return 0 when they expose the indicator.
309+
<!-- https://github.com/openssl/openssl/pull/32913 -->
310+
311+
*Shane Lontis*
312+
313+
* Changed the compiler flags supplied to MSVC targets to no longer include
314+
`/Gs0` (resetting the minimum memory size occupied by local variables
315+
for including stack probes to the default value of 4096), as it led
316+
to mis-compilation of MD4 C implementation on ARM64.
317+
<!-- https://github.com/openssl/openssl/pull/32872 -->
318+
319+
*Norbert Pócs*
320+
31321
### Changes between 3.5.7 and 3.5.8 [25 Aug 2026]
32322

33323
* Fixed QUIC server being able to trigger double free when processing `INITIAL`
@@ -22521,22 +22811,35 @@ ndif
2252122811
[CVE-2026-34181]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34181
2252222812
[CVE-2026-34182]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34182
2252322813
[CVE-2026-34183]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34183
22814+
[CVE-2026-35189]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-35189
22815+
[CVE-2026-35191]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-35191
2252422816
[CVE-2026-42764]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42764
2252522817
[CVE-2026-42766]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42766
2252622818
[CVE-2026-42767]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42767
2252722819
[CVE-2026-42768]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42768
2252822820
[CVE-2026-42769]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42769
2252922821
[CVE-2026-42770]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42770
22822+
[CVE-2026-42772]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42772
2253022823
[CVE-2026-45445]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45445
2253122824
[CVE-2026-45446]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45446
2253222825
[CVE-2026-45447]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45447
22826+
[CVE-2026-54872]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54872
22827+
[CVE-2026-54873]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54873
2253322828
[CVE-2026-54874]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54874
22829+
[CVE-2026-54875]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54875
2253422830
[CVE-2026-63072]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63072
2253522831
[CVE-2026-63073]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63073
2253622832
[CVE-2026-63074]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63074
2253722833
[CVE-2026-63075]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63075
2253822834
[CVE-2026-63076]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63076
22835+
[CVE-2026-72897]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-72897
2253922836
[CVE-2026-75803]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75803
22837+
[CVE-2026-75804]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75804
22838+
[CVE-2026-75805]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75805
22839+
[CVE-2026-75806]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75806
22840+
[CVE-2026-77696]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-77696
22841+
[CVE-2026-84782]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782
22842+
[CVE-2026-84784]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-84784
2254022843
[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations
2254122844
[RFC 2578 (STD 58), section 3.5]: https://datatracker.ietf.org/doc/html/rfc2578#section-3.5
2254222845
[RFC 3211]: https://datatracker.ietf.org/doc/html/rfc3211
@@ -22545,3 +22848,4 @@ ndif
2254522848
[RFC 8446]: https://datatracker.ietf.org/doc/html/rfc8446
2254622849
[RFC 8446 Section 4.6.1]: https://datatracker.ietf.org/doc/html/rfc8446#section-4.6.1
2254722850
[RFC 8452]: https://datatracker.ietf.org/doc/html/rfc8452
22851+
[RFC 9000]: https://datatracker.ietf.org/doc/html/rfc9000

‎deps/openssl/openssl/Configurations/10-main.conf‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1566,7 +1566,7 @@ my %targets = (
15661566
template => 1,
15671567
CFLAGS => add(picker(debug => '/Od',
15681568
release => '/O2')),
1569-
cflags => add(picker(default => '/Gs0 /GF /Gy',
1569+
cflags => add(picker(default => '/GF /Gy',
15701570
debug =>
15711571
sub {
15721572
($disabled{shared} ? "" : "/MDd");

0 commit comments

Comments
 (0)