-
-
Notifications
You must be signed in to change notification settings - Fork 34.4k
Update OpenSSL used in binary releases per CVE-2023-0464 #103142
Copy link
Copy link
Closed
Labels
3.10only security fixesonly security fixes3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13bugs and security fixesbugs and security fixes3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of liferelease-blockertopic-SSLtype-securityA security issueA security issue
Metadata
Metadata
Labels
3.10only security fixesonly security fixes3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13bugs and security fixesbugs and security fixes3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of liferelease-blockertopic-SSLtype-securityA security issueA security issue
Projects
Status
Done
https://nvd.nist.gov/vuln/detail/CVE-2023-0464
We need OpenSSL >= 1.1.1u | 3.0.9 | 3.1.1.
We've got patch releases coming up soon, we should be able to just bump the versions before then.
(note: at the time of this writing OpenSSL hasn't even released those updated versions)
Linked PRs