diff options
| author | tb <> | 2025-09-30 12:54:18 +0000 |
|---|---|---|
| committer | tb <> | 2025-09-30 12:54:18 +0000 |
| commit | 2f913441f29f1f81d45eb8d13b12bdfd75a57d70 (patch) | |
| tree | 6bd735c3de0d6ebec02d4b9896dbc6061659379e /src/lib/libssl/tls13_server.c | |
| parent | 9d824f57e18af2ec9fe3dab311be62b1e32eda9b (diff) | |
| download | openbsd-2f913441f29f1f81d45eb8d13b12bdfd75a57d70.tar.gz openbsd-2f913441f29f1f81d45eb8d13b12bdfd75a57d70.tar.bz2 openbsd-2f913441f29f1f81d45eb8d13b12bdfd75a57d70.zip | |
cms_RecipientInfo_pwri_crypt: fix incorrect return checklibressl-v4.1.1
cms_RecipientInfo_pwri_crypt: plug leak of kekalg
cms: fix incorrect length check in kek_unwrap_key()
An incorrect length check can result in a 4-byte overwrite and an
8-byte overread.
From Stanislav Fort and Viktor Dukhovni via OpenSSL.
CVE-2025-9230.
ok jsing
this is errata/7.7/010_libcrypto.patch.sig
Diffstat (limited to 'src/lib/libssl/tls13_server.c')
0 files changed, 0 insertions, 0 deletions
