Tuesday, September 30, 2025

LibreSSL 4.0.1, 4.1.1 released

We have released LibreSSL 4.0.1 and 4.1.1, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon.

They include the following changes from LibreSSL 4.0.0 and 4.1.0:

* Bugfixes
- OpenBSD 7.6 errata 023, OpenBSD 7.7 errata 010.
An incorrect length check can result in a 4-byte overwrite and an
8-byte overread.
From Stanislav Fort and Viktor Dukhovni via OpenSSL.
CVE-2025-9230.

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.

No comments:

Post a Comment