BSDSec

deadsimple BSD Security Advisories and Announcements

LibreSSL 3.5.3 released

We have released LibreSSL 3.5.3, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon.

It includes the following reliability fix:

  * Fix d2i_ASN1_OBJECT(). A confusion of two CBS resulted in advancing
    the passed *der_in pointer incorrectly. Thanks to Aram Sargsyan for
    reporting the issue and testing the fix.

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.