deps: upgrade openssl sources to quictls/openssl-3.0.16 · nodejs/node@4056c1f · GitHub
Skip to content

Commit 4056c1f

Browse files
nodejs-github-bottargos
authored andcommitted
deps: upgrade openssl sources to quictls/openssl-3.0.16
PR-URL: #57335 Reviewed-By: Richard Lau <rlau@redhat.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Filip Skokan <panva.ip@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
1 parent 5c20dcc commit 4056c1f

232 files changed

Lines changed: 2754 additions & 3535 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

deps/openssl/openssl/CHANGES.md

Lines changed: 30 additions & 3 deletions

deps/openssl/openssl/Configurations/unix-Makefile.tmpl

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1688,7 +1688,7 @@ EOF
16881688
} elsif ($makedep_scheme eq 'gcc' && !grep /\.rc$/, @srcs) {
16891689
$recipe .= <<"EOF";
16901690
$obj: $deps
1691-
$cmd $incs $defs $cmdflags -MMD -MF $dep.tmp -MT \$\@ -c -o \$\@ $srcs
1691+
$cmd $incs $defs $cmdflags -MMD -MF $dep.tmp -c -o \$\@ $srcs
16921692
\@touch $dep.tmp
16931693
\@if cmp $dep.tmp $dep > /dev/null 2> /dev/null; then \\
16941694
rm -f $dep.tmp; \\

deps/openssl/openssl/Configure

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -467,7 +467,6 @@ my @disablables = (
467467
"poly1305",
468468
"posix-io",
469469
"psk",
470-
"quic",
471470
"rc2",
472471
"rc4",
473472
"rc5",
@@ -578,15 +577,14 @@ my @disable_cascades = (
578577
"sm3", "sm4", "srp",
579578
"srtp", "ssl3-method", "ssl-trace",
580579
"ts", "ui-console", "whirlpool",
581-
"quic",
582580
"fips-securitychecks" ],
583581
sub { $config{processor} eq "386" }
584582
=> [ "sse2" ],
585583
"ssl" => [ "ssl3" ],
586584
"ssl3-method" => [ "ssl3" ],
587585
"zlib" => [ "zlib-dynamic" ],
588586
"des" => [ "mdc2" ],
589-
"ec" => [ "ec2m", "ecdsa", "ecdh", "sm2", "gost", "quic" ],
587+
"ec" => [ "ec2m", "ecdsa", "ecdh", "sm2", "gost" ],
590588
"dgram" => [ "dtls", "sctp" ],
591589
"sock" => [ "dgram" ],
592590
"dtls" => [ @dtls ],
@@ -637,7 +635,6 @@ my @disable_cascades = (
637635
"legacy" => [ "md2" ],
638636

639637
"cmp" => [ "crmf" ],
640-
"tls1_3" => [ "quic" ],
641638

642639
"fips" => [ "fips-securitychecks", "acvp-tests" ],
643640

deps/openssl/openssl/INSTALL.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -829,10 +829,6 @@ Don't use POSIX IO capabilities.
829829

830830
Don't build support for Pre-Shared Key based ciphersuites.
831831

832-
### no-quic
833-
834-
Don't build support for QUIC API from BoringSSL.
835-
836832
### no-rdrand
837833

838834
Don't use hardware RDRAND capabilities.

deps/openssl/openssl/NEWS.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,20 @@ OpenSSL Releases
1818
OpenSSL 3.0
1919
-----------
2020

21+
### Major changes between OpenSSL 3.0.15 and OpenSSL 3.0.16 [11 Feb 2025]
22+
23+
OpenSSL 3.0.16 is a security patch release. The most severe CVE fixed in this
24+
release is Low.
25+
26+
This release incorporates the following bug fixes and mitigations:
27+
28+
* Fixed timing side-channel in ECDSA signature computation.
29+
([CVE-2024-13176])
30+
31+
* Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic
32+
curve parameters.
33+
([CVE-2024-9143])
34+
2135
### Major changes between OpenSSL 3.0.14 and OpenSSL 3.0.15 [3 Sep 2024]
2236

2337
OpenSSL 3.0.15 is a security patch release. The most severe CVE fixed in this
@@ -1495,6 +1509,8 @@ OpenSSL 0.9.x
14951509

14961510
<!-- Links -->
14971511

1512+
[CVE-2024-13176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176
1513+
[CVE-2024-9143]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-9143
14981514
[CVE-2024-6119]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-6119
14991515
[CVE-2024-5535]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-5535
15001516
[CVE-2024-4741]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4741

deps/openssl/openssl/NOTES-NONSTOP.md

Lines changed: 2 additions & 5 deletions

deps/openssl/openssl/README-OpenSSL.md

Lines changed: 0 additions & 224 deletions
This file was deleted.

0 commit comments

Comments
 (0)