HomeFreeBSD

Fix multiple security issues in OpenSSL.

Description

Fix multiple security issues in OpenSSL.

Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230)
Timing side-channel in SM2 algorithm on 64 bit ARM (CVE-2025-9231)
Out-of-bounds read in HTTP client no_proxy handling (CVE-2025-9232)

Obtained from: OpenSSL
Approved by: so
Security: FreeBSD-SA-25:08.openssl
Security: CVE-2025-9230
Security: CVE-2025-9231
Security: CVE-2025-9232

(cherry picked from commit aa1afb69dcedfc68859815987c46997500f834c3)

Details

Provenance
gordonAuthored on Sep 30 2025, 3:23 PM
Parents
rG053b8cb7602c: dtrace: Use a size_t to represent a buffer size in the printm action
Branches
Unknown
Tags
Unknown