BSDSec

deadsimple BSD Security Advisories and Announcements

LibreSSL 3.7.3, 3.6.3 Released

We have released LibreSSL 3.6.3 and 3.7.3, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon.

They include the following fixes:

  * Bug fix
    - Hostflags in the verify parameters would not propagate from an
      SSL_CTX to newly created SSL.
  * Reliability fix
    - A double free or use after free could occur after SSL_clear(3).

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.