<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/pepe2k/package/libs, branch v23.05.5</title>
<subtitle>Staging tree of Piotr Dymacz</subtitle>
<id>https://git.openwrt.org/openwrt/staging/pepe2k/atom?h=v23.05.5</id>
<link rel='self' href='https://git.openwrt.org/openwrt/staging/pepe2k/atom?h=v23.05.5'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/'/>
<updated>2024-09-15T00:03:25Z</updated>
<entry>
<title>ncurses: Fix path in ncursesw.pc</title>
<updated>2024-09-15T00:03:25Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2024-07-27T17:29:04Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=461102d99cdd5e380e3b23105e69d939199ca6bc'/>
<id>urn:sha1:461102d99cdd5e380e3b23105e69d939199ca6bc</id>
<content type='text'>
The file contains the the /usr/lib path from the toolchain directory and
not from the target directory. The /usr/lib directory for the toolchain
is empty and the shared library is not in the specified paths. On RISCV
the linker of util-linux was finding the libncursesw.so in my host
system, tried to link against it and failed. Fix the .pc file.

Fixes: #15942
Co-authored-by: Thomas Weißschuh &lt;thomas@t-8ch.de&gt;
Link: https://github.com/openwrt/openwrt/pull/16018
Signed-off-by: Robert Marko &lt;robimarko@gmail.com&gt;
(cherry picked from commit 91573ac145aa70a12b0984ec75507ac648569240)
Link: https://github.com/openwrt/openwrt/pull/16390
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>openssl: update to 3.0.15</title>
<updated>2024-09-14T15:04:20Z</updated>
<author>
<name>Ivan Pavlov</name>
</author>
<published>2024-09-05T08:21:57Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=4fa16c1e24cee65fe61fd7078bffd1a33ecf51f8'/>
<id>urn:sha1:4fa16c1e24cee65fe61fd7078bffd1a33ecf51f8</id>
<content type='text'>
OpenSSL 3.0.15 is a security patch release. The most severe CVE fixed in this release is Moderate.

This release incorporates the following bug fixes and mitigations:

  * Fixed possible denial of service in X.509 name checks (CVE-2024-6119)

  * Fixed possible buffer overread in SSL_select_next_proto() (CVE-2024-5535)

Added github releases url as source mirror

Signed-off-by: Ivan Pavlov &lt;AuthorReflex@gmail.com&gt;
Link: https://github.com/openwrt/openwrt/pull/16332
(cherry picked from commit 62d3773bf19a3e2f39935c08a8b5b2186777f314)
Link: https://github.com/openwrt/openwrt/pull/16346
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>mbedtls: Update to 2.28.9</title>
<updated>2024-09-14T15:02:22Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2024-09-11T21:03:50Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=a0ebff651d41ce7c892b24785b0edc04fba1341c'/>
<id>urn:sha1:a0ebff651d41ce7c892b24785b0edc04fba1341c</id>
<content type='text'>
This contains a fix for:
CVE-2024-45157:
Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does
not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when
MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.

Link: https://github.com/openwrt/openwrt/pull/16367
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>wolfssl: Update to version 5.7.2</title>
<updated>2024-07-15T22:05:18Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2024-07-14T23:06:38Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=84b000e5d0b490306f3d1d0641d84f0e79931150'/>
<id>urn:sha1:84b000e5d0b490306f3d1d0641d84f0e79931150</id>
<content type='text'>
This fixes multiple security problems:
 * [Medium] CVE-2024-1544
   Potential ECDSA nonce side channel attack in versions of wolfSSL before 5.6.6 with wc_ecc_sign_hash calls.

 * [Medium] CVE-2024-5288
   A private key blinding operation, enabled by defining the macro WOLFSSL_BLIND_PRIVATE_KEY, was added to mitigate a potential row hammer attack on ECC operations.

 * [Low] When parsing a provided maliciously crafted certificate directly using wolfSSL API, outside of a TLS connection, a certificate with an excessively large number of extensions could lead to a potential DoS.

 * [Low] CVE-2024-5991
   In the function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked.

 * [Medium] CVE-2024-5814
   A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection.

 * [Medium] OCSP stapling version 2 response verification bypass issue when a crafted response of length 0 is received.

 * [Medium] OCSP stapling version 2 revocation bypass with a retry of a TLS connection attempt.

Unset DISABLE_NLS to prevent setting the unsupported configuration
option --disable-nls which breaks the build now.

Link: https://github.com/openwrt/openwrt/pull/15948
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
(cherry picked from commit 3a0232ffd33f2dc894c671d90de6b2766399f4dc)
</content>
</entry>
<entry>
<title>libxml2: add host build dependency on libiconv-full</title>
<updated>2024-07-08T19:13:26Z</updated>
<author>
<name>Felix Fietkau</name>
</author>
<published>2024-04-04T11:45:33Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=7d135dc038b0986522c68545d648fcb6a3fb1874'/>
<id>urn:sha1:7d135dc038b0986522c68545d648fcb6a3fb1874</id>
<content type='text'>
Fixes build on macOS

Signed-off-by: Felix Fietkau &lt;nbd@nbd.name&gt;
(cherry picked from commit 4ef13c4a49708d361df663a6e42e6e114a71c020)
Link: https://github.com/openwrt/openwrt/pull/15898
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>mbedtls: Update to 2.28.8</title>
<updated>2024-07-08T19:13:26Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2024-04-21T15:40:09Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=dee4309bdfba8b95c6399bd2f4c10a66350e679c'/>
<id>urn:sha1:dee4309bdfba8b95c6399bd2f4c10a66350e679c</id>
<content type='text'>
This contains a fix for:
CVE-2024-28960: An issue was discovered in Mbed TLS 2.18.0 through 2.28.x
before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto
API mishandles shared memory.

(cherry picked from commit 360ac07eb933feaf29bb031f788f0bf81c473be7)
Link: https://github.com/openwrt/openwrt/pull/15898
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>package/libs/libjson-c: fix PKG_CPE_ID</title>
<updated>2024-07-06T16:31:14Z</updated>
<author>
<name>Fabrice Fontaine</name>
</author>
<published>2024-04-26T15:47:24Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=8c20083c1de958aff7e32406278dce18a1fed723'/>
<id>urn:sha1:8c20083c1de958aff7e32406278dce18a1fed723</id>
<content type='text'>
cpe:/a:json-c:json-c is the correct CPE ID for libjson-c:
https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:json-c:json-c

Fixes: c61a2395140d92cdd37d3d6ee43a765427e8e318 (add PKG_CPE_ID ids to package and tools)

Signed-off-by: Fabrice Fontaine &lt;fontaine.fabrice@gmail.com&gt;
Link: https://github.com/openwrt/openwrt/pull/15292
Signed-off-by: Robert Marko &lt;robimarko@gmail.com&gt;
(cherry picked from commit a4f723e04ed245819fe320f472a4ff2b4eda00fb)
Link: https://github.com/openwrt/openwrt/pull/15881
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>package/libs/pcre2: fix PKG_CPE_ID</title>
<updated>2024-07-06T16:31:14Z</updated>
<author>
<name>Fabrice Fontaine</name>
</author>
<published>2024-04-26T13:09:50Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=b110c337d30e783c91f4ba0ceca266d3d32a38b2'/>
<id>urn:sha1:b110c337d30e783c91f4ba0ceca266d3d32a38b2</id>
<content type='text'>
cpe:/a:pcre:pcre2 is the correct CPE ID for pcre2:
https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:pcre:pcre2

Fixes: c39b0646f3f2d96d40f601209859175af8537b6d (pcre2: import pcre2 from packages feed)

Signed-off-by: Fabrice Fontaine &lt;fontaine.fabrice@gmail.com&gt;
(cherry picked from commit 27d1ebb46adfd58db9a8034336c2d85b41f617f9)
Link: https://github.com/openwrt/openwrt/pull/15881
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>openssl: conditionally disable engine section</title>
<updated>2024-07-06T16:29:23Z</updated>
<author>
<name>Sean Khan</name>
</author>
<published>2024-06-09T01:02:30Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=318db3bde4615b09738851059e8b1a42a9d768b8'/>
<id>urn:sha1:318db3bde4615b09738851059e8b1a42a9d768b8</id>
<content type='text'>
Currently, the build option to enable/disable engine support isn't
reflected in the final '/etc/ssl/openssl.cnf' config. It assumes `engines`
is always enabled, producing an error whenever running any
commands in openssl util or programs that explicitly use settings
from '/etc/ssl/openssl.cnf'.

```
➤ openssl version
FATAL: Startup failure (dev note: apps_startup()) for openssl
307D1EA97F000000:error:12800067:lib(37):dlfcn_load:reason(103):crypto/dso/dso_dlfcn.c:118:filename(libengines.so):
Error loading shared library libengines.so: No such file or directory
307D1EA97F000000:error:12800067:lib(37):DSO_load:reason(103):crypto/dso/dso_lib.c:152:
307D1EA97F000000:error:0700006E:lib(14):module_load_dso:reason(110):crypto/conf/conf_mod.c:321:module=engines, path=engines
307D1EA97F000000:error:07000071:lib(14):module_run:reason(113):crypto/conf/conf_mod.c:266:module=engines
```

Build should check for the `CONFIG_OPENSSL_ENGINE` option, and comment out `engines`
if not explicitly enabled.

Example:
```
[openssl_init]
providers = provider_sect
```

After this change, openssl util works correctly.

```
➤ openssl version
OpenSSL 3.0.14 4 Jun 2024 (Library: OpenSSL 3.0.14 4 Jun 2024)
```

Signed-off-by: Sean Khan &lt;datapronix@protonmail.com&gt;
Link: https://github.com/openwrt/openwrt/pull/15661
Signed-off-by: Robert Marko &lt;robimarko@gmail.com&gt;
(cherry picked from commit 31ec4515c3c14704d669156d87e2af5eeb5420e4)
Link: https://github.com/openwrt/openwrt/pull/15873
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>openssl: update to 3.0.14</title>
<updated>2024-07-06T16:29:23Z</updated>
<author>
<name>John Audia</name>
</author>
<published>2024-06-05T19:55:29Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=4aabbd6746e8be68401ce6b742499d81f1b4b721'/>
<id>urn:sha1:4aabbd6746e8be68401ce6b742499d81f1b4b721</id>
<content type='text'>
Major changes between OpenSSL 3.0.13 and OpenSSL 3.0.14 [04-Jun-2024]

* Fixed potential use after free after SSL_free_buffers() is called.
  [CVE-2024-4741]
* Fixed checking excessively long DSA keys or parameters may be very slow.
  [CVE-2024-4603]
* Fixed an issue where some non-default TLS server configurations can cause
  unbounded memory growth when processing TLSv1.3 sessions. An attacker may
  exploit certain server configurations to trigger unbounded memory growth that
  would lead to a Denial of Service.  [CVE-2024-2511]
* New atexit configuration switch, which controls whether the OPENSSL_cleanup
  is registered when libcrypto is unloaded. This can be used on platforms
  where using atexit() from shared libraries causes crashes on exit

Signed-off-by: John Audia &lt;therealgraysky@proton.me&gt;

Build system: x86/64
Build-tested: x86/64/AMD Cezanne

(cherry picked from commit bac2f1bed6db5da166aad7b1091c2e9af0ffef5d)
Link: https://github.com/openwrt/openwrt/pull/15873
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
</feed>
