difos/package/libs/openssl/patches
John Audia e2cdcf8e46 openssl: update to 3.5.1
Automatically rebased: 100-Configure-afalg-support.patch

Changes between 3.5.0 and 3.5.1:
Fix x509 application adds trusted use instead of rejected use.
Issue summary: Use of -addreject option with the openssl x509 application
adds a trusted use instead of a rejected use for a certificate.

Impact summary: If a user intends to make a trusted certificate rejected
for a particular use it will be instead marked as trusted for that use.
(CVE-2025-4575)

Aligned the behaviour of TLS and DTLS in the event of a no_renegotiation
alert being received. Older versions of OpenSSL failed with DTLS if a
no_renegotiation alert was received. All versions of OpenSSL do this for TLS.
From 3.2 a bug was exposed that meant that DTLS ignored no_rengotiation.
We have now restored the original behaviour and brought DTLS back into line
with TLS.

Signed-off-by: John Audia <therealgraysky@proton.me>
Link: https://github.com/openwrt/openwrt/pull/19283
Signed-off-by: Robert Marko <robimarko@gmail.com>
2025-07-03 13:03:39 +02:00
..
100-Configure-afalg-support.patch openssl: update to 3.5.1 2025-07-03 13:03:39 +02:00
110-openwrt_targets.patch openssl: add linux64-loongarch64 into the targets list 2024-05-04 14:14:24 +08:00
120-strip-cflags-from-binary.patch openssl: Update to 3.5.0 2025-05-18 13:40:17 +02:00
130-dont-build-fuzz-docs.patch openssl: bump to 3.0.8 2023-02-20 11:24:17 +01:00
140-allow-prefer-chacha20.patch openssl: Update to 3.5.0 2025-05-18 13:40:17 +02:00
150-openssl.cnf-add-engines-conf.patch openssl: add legacy provider 2023-04-05 08:24:49 -03:00
500-e_devcrypto-default-to-not-use-digests-in-engine.patch openssl: Update to 3.5.0 2025-05-18 13:40:17 +02:00
510-e_devcrypto-ignore-error-when-closing-session.patch openssl: Update to 3.5.0 2025-05-18 13:40:17 +02:00