<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/hauke/package/libs, branch v19.07.7</title>
<subtitle>Hauke Mehrtens staging tree</subtitle>
<id>https://git.openwrt.org/openwrt/staging/hauke/atom?h=v19.07.7</id>
<link rel='self' href='https://git.openwrt.org/openwrt/staging/hauke/atom?h=v19.07.7'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/'/>
<updated>2021-02-09T23:23:45Z</updated>
<entry>
<title>wolfssl: Backport fix for CVE-2021-3336</title>
<updated>2021-02-09T23:23:45Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2021-02-08T23:53:09Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=d5a8e8587893e63d97d59b51287972959cb73154'/>
<id>urn:sha1:d5a8e8587893e63d97d59b51287972959cb73154</id>
<content type='text'>
This should fix CVE-2021-3336:
DoTls13CertificateVerify in tls13.c in wolfSSL through 4.6.0 does not
cease processing for certain anomalous peer behavior (sending an
ED22519, ED448, ECC, or RSA signature without the corresponding
certificate).

The patch is backported from the upstream wolfssl development branch.

Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
(cherry picked from commit 1f559cafe5cc1193a5962d40a2d938c66c783171)
</content>
</entry>
<entry>
<title>wolfssl: enable HAVE_SECRET_CALLBACK</title>
<updated>2021-02-02T09:09:37Z</updated>
<author>
<name>Felix Fietkau</name>
</author>
<published>2021-01-02T13:36:03Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=3100649458387f844aa447bdb3bbac3e4d7e32da'/>
<id>urn:sha1:3100649458387f844aa447bdb3bbac3e4d7e32da</id>
<content type='text'>
Fixes wpad-wolfssl build

Signed-off-by: Felix Fietkau &lt;nbd@nbd.name&gt;
(cherry picked from commit 55e23f2c02ae95e84613ed7d1cbf8aba557b8682)
</content>
</entry>
<entry>
<title>wolfssl: Fix hostapd build with wolfssl 4.6.0</title>
<updated>2021-02-02T09:09:19Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2021-01-01T21:04:18Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=e9d2aa9dc6a5663e3d43fc817d276582842134bb'/>
<id>urn:sha1:e9d2aa9dc6a5663e3d43fc817d276582842134bb</id>
<content type='text'>
This fixes the following build problem in hostapd:
mipsel-openwrt-linux-musl/bin/ld: /builder/shared-workdir/build/tmp/ccN4Wwer.ltrans7.ltrans.o: in function `crypto_ec_point_add':
&lt;artificial&gt;:(.text.crypto_ec_point_add+0x170): undefined reference to `ecc_projective_add_point'
mipsel-openwrt-linux-musl/bin/ld: &lt;artificial&gt;:(.text.crypto_ec_point_add+0x18c): undefined reference to `ecc_map'
mipsel-openwrt-linux-musl/bin/ld: /builder/shared-workdir/build/tmp/ccN4Wwer.ltrans7.ltrans.o: in function `crypto_ec_point_to_bin':
&lt;artificial&gt;:(.text.crypto_ec_point_to_bin+0x40): undefined reference to `ecc_map'

Fixes: ba40da9045f7 ("wolfssl: Update to v4.6.0-stable")
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
(cherry picked from commit e7d0d2e9dcaa0ff1197fb7beee139b6a5bd35c79)
</content>
</entry>
<entry>
<title>wolfssl: Update to v4.6.0-stable</title>
<updated>2021-02-02T09:08:11Z</updated>
<author>
<name>Eneas U de Queiroz</name>
</author>
<published>2020-12-29T17:49:20Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=2044c01de8f214c43c6c13dcb538e3730f97a7f8'/>
<id>urn:sha1:2044c01de8f214c43c6c13dcb538e3730f97a7f8</id>
<content type='text'>
This version fixes a large number of bugs and fixes CVE-2020-36177.

Full changelog at:
https://www.wolfssl.com/docs/wolfssl-changelog/
or, as part of the version's README.md:
https://github.com/wolfSSL/wolfssl/blob/v4.6.0-stable/README.md

Due a number of API additions, size increases from 374.7K to 408.8K for
arm_cortex_a9_vfpv3-d16.  The ABI does not change from previous version.

Backported patches were removed; remaining patch was refreshed.

Signed-off-by: Eneas U de Queiroz &lt;cotequeiroz@gmail.com&gt;
[added reference to CVE]
Signed-off-by: Petr Štetiar &lt;ynezz@true.cz&gt;
(cherry picked from commit ba40da9045f77feb04abe63eb8a92f13f9efe471)
</content>
</entry>
<entry>
<title>mbedtls: update to 2.16.9</title>
<updated>2021-01-18T00:42:26Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2021-01-04T00:28:43Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=e30d3ea95f72741b79fec376cf37d0db99633110'/>
<id>urn:sha1:e30d3ea95f72741b79fec376cf37d0db99633110</id>
<content type='text'>
Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
(cherry picked from commit f13b623f5e53a72b65f45cbaf56c73df35e70ed2)
</content>
</entry>
<entry>
<title>openssl: update to 1.1.1i</title>
<updated>2020-12-16T20:31:52Z</updated>
<author>
<name>Eneas U de Queiroz</name>
</author>
<published>2020-12-11T11:39:35Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=c03f0182202e99de3676f5bb4549c61c85d55ed4'/>
<id>urn:sha1:c03f0182202e99de3676f5bb4549c61c85d55ed4</id>
<content type='text'>
Fixes: CVE-2020-1971, defined as high severity, summarized as:
NULL pointer deref in GENERAL_NAME_cmp function can lead to a DOS
attack.

Signed-off-by: Eneas U de Queiroz &lt;cotequeiroz@gmail.com&gt;
(cherry picked from commit 882ca13d923796438fd06badeb00dc95b7eb1467)
</content>
</entry>
<entry>
<title>openssl: bump to 1.1.1h</title>
<updated>2020-09-28T15:14:31Z</updated>
<author>
<name>Eneas U de Queiroz</name>
</author>
<published>2020-09-28T10:46:33Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=8076fb59ab1c4a07fc4c4ea40570b354ef5d8cc0'/>
<id>urn:sha1:8076fb59ab1c4a07fc4c4ea40570b354ef5d8cc0</id>
<content type='text'>
This is a bug-fix release.  Patches were refreshed.

Signed-off-by: Eneas U de Queiroz &lt;cotequeiroz@gmail.com&gt;
(cherry picked from commit 475838de1a33d49d1a0b81aad374a8db6dd2b3c8)
</content>
</entry>
<entry>
<title>wolfssl: Update to version 4.5.0</title>
<updated>2020-09-02T13:46:42Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2020-08-24T10:11:29Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=403039c562e16f4242e3485d8f076ea726dd8744'/>
<id>urn:sha1:403039c562e16f4242e3485d8f076ea726dd8744</id>
<content type='text'>
This fixes the following security problems:
* In earlier versions of wolfSSL there exists a potential man in the
  middle attack on TLS 1.3 clients.
* Denial of service attack on TLS 1.3 servers from repetitively sending
  ChangeCipherSpecs messages. (CVE-2020-12457)
* Potential cache timing attacks on public key operations in builds that
  are not using SP (single precision). (CVE-2020-15309)
* When using SGX with EC scalar multiplication the possibility of side-
  channel attacks are present.
* Leak of private key in the case that PEM format private keys are
  bundled in with PEM certificates into a single file.
* During the handshake, clear application_data messages in epoch 0 are
  processed and returned to the application.

Full changelog:
https://www.wolfssl.com/docs/wolfssl-changelog/

Fix a build error on big endian systems by backporting a pull request:
https://github.com/wolfSSL/wolfssl/pull/3255

The size of the ipk increases on mips BE by 1.4%
old:
libwolfssl24_4.4.0-stable-2_mips_24kc.ipk:	386246
new:
libwolfssl24_4.5.0-stable-1_mips_24kc.ipk:	391528

Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
(cherry picked from commit 00722a720c778e623d6f37af3a3b4e43b29c3fe8)
</content>
</entry>
<entry>
<title>wolfssl: use -fomit-frame-pointer to fix asm error</title>
<updated>2020-09-02T13:46:36Z</updated>
<author>
<name>Eneas U de Queiroz</name>
</author>
<published>2020-05-26T13:45:22Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=dc61110adc6cf579d971ffd032aed677d91da674'/>
<id>urn:sha1:dc61110adc6cf579d971ffd032aed677d91da674</id>
<content type='text'>
32-bit x86 fail to compile fast-math feature when compiled with frame
pointer, which uses a register used in a couple of inline asm functions.

Previous versions of wolfssl had this by default.  Keeping an extra
register available may increase performance, so it's being restored for
all architectures.

Signed-off-by: Eneas U de Queiroz &lt;cotequeiroz@gmail.com&gt;
(cherry picked from commit 750d52f6c90e2a144c250779741607f0cb306a94)
</content>
</entry>
<entry>
<title>wolfssl: update to 4.4.0-stable</title>
<updated>2020-09-02T13:46:30Z</updated>
<author>
<name>Eneas U de Queiroz</name>
</author>
<published>2020-05-01T15:06:48Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/hauke/commit/?id=ad38a2ae61e57252c081eb8d55ad4e90f010e48a'/>
<id>urn:sha1:ad38a2ae61e57252c081eb8d55ad4e90f010e48a</id>
<content type='text'>
This version adds many bugfixes, including a couple of security
vulnerabilities:
 - For fast math (enabled by wpa_supplicant option), use a constant time
   modular inverse when mapping to affine when operation involves a
   private key - keygen, calc shared secret, sign.
 - Change constant time and cache resistant ECC mulmod. Ensure points
   being operated on change to make constant time.

Signed-off-by: Eneas U de Queiroz &lt;cotequeiroz@gmail.com&gt;
(cherry picked from commit 3481f6ffc79f46fc7ba86a4cc15ad958e99b5a82)
</content>
</entry>
</feed>
