BSDSec

deadsimple BSD Security Advisories and Announcements

LibreSSL 3.3.5 / 3.2.7 Released

We have released LibreSSL 3.3.5 and 3.2.7, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon.

It includes the following fixes:

  * A stack overread could occur when checking X.509 name constraints.
    From GoldBinocle on GitHub.

  * Enable X509_V_FLAG_TRUSTED_FIRST by default in the legacy verifier.
    This compensates for the expiry of the DST Root X3 certificate.

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.