openssl_3: 3.0.14 -> 3.0.15

Contains two CVE fixes.

* Fixed possible denial of service in X.509 name checks. (CVE-2024-6119)
* Fixed possible buffer overread in SSL_select_next_proto(). (CVE-2024-5535)

Changelog: https://github.com/openssl/openssl/blob/openssl-3.0/CHANGES.md#changes-between-3014-and-3015-3-sep-2024

Signed-off-by: Markus Theil <theil.markus@gmail.com>
This commit is contained in:
Markus Theil
2024-09-16 09:44:41 +02:00
parent 64ab30598c
commit 6fef5775cc
@@ -286,8 +286,8 @@ in {
};
openssl_3 = common {
version = "3.0.14";
hash = "sha256-7soDXU3U6E/CWEbZUtpil0hK+gZQpvhMaC453zpBI8o=";
version = "3.0.15";
hash = "sha256-I8Zm0O3yDxQkmz2PA2isrumrWFsJ4d6CEHxm4fPslTM=";
patches = [
./3.0/nix-ssl-cert-file.patch
@@ -296,8 +296,6 @@ in {
# This patch disables build-time detection.
./3.0/openssl-disable-kernel-detection.patch
./3.3/CVE-2024-5535.patch
(if stdenv.hostPlatform.isDarwin
then ./use-etc-ssl-certs-darwin.patch
else ./use-etc-ssl-certs.patch)