Skip to content

openssl 3.5.9 - #167

Merged
DevomB merged 1 commit into
mainfrom
openssl-3.5.9
Sep 30, 2026
Merged

DevomB merged 1 commit into
mainfrom
openssl-3.5.9

Conversation

@DevomB

@DevomB DevomB commented Sep 30, 2026

Copy link
Copy Markdown
Owner

OpenSSL released 3.5.9, 3.6.5 and 4.0.3 on 2026-09-29. The 3.5 LTS release carries the same fixes as 3.6.5: CVE-2026-84782 (DTLS retransmission from a stale buffer offset, high), CVE-2026-35189 (excessive memory allocation in relative CRLDP processing, low) and two QUIC lows; the advisory names 3.5 as affected by all four. The pin moves from 3.5.8 to 3.5.9, the lock records the tarball's hash (the publisher's .sha256 agrees), and the signature verifies against the publisher's pubkeys.asc: the signing subkey C46ED3F2… of the pinned 2026 primary B146647E…, the same subkey that signed 3.5.8, so the gate pins nothing new. The review row moves to 3.5.9 reviewed up to 3.6.5, which turns main's pin gate green again.

… carries (CVE-2026-84782 DTLS retransmission, CVE-2026-35189 CRLDP memory, two QUIC lows), signed by the same subkey of the pinned 2026 key as 3.5.8
@DevomB
DevomB merged commit 52682fc into main Sep 30, 2026
20 of 21 checks passed
@DevomB
DevomB deleted the openssl-3.5.9 branch September 30, 2026 07:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant