mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-14 18:24:01 -09:00
https://openssl-library.org/post/2026-04-07-release-announcement/ Fixes the following vulnerabilities: CVE-2026-31790 - Incorrect Failure Handling in RSA KEM RSASVE Encapsulation. CVE-2026-28386 - Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 Support. CVE-2026-28387 - Potential Use-after-free in DANE Client Code. CVE-2026-28388 - NULL Pointer Dereference When Processing a Delta CRL. CVE-2026-28389 - Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo. CVE-2026-28390 - Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo. CVE-2026-31789 - Heap Buffer Overflow in Hexadecimal Conversion. Removed patch 0004 which is included in this release, merged in:7936b4c415Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit58d2330b62) Signed-off-by: Thomas Perale <thomas.perale@mind.be>