summaryrefslogtreecommitdiff
path: root/MdePkg/Library/StackCheckLibNull/StackCheckLibNullMsvc.c
diff options
context:
space:
mode:
authorGordon Tetlow <gordon@FreeBSD.org>2026-04-29 08:23:24 +0000
committerMark Johnston <markj@FreeBSD.org>2026-06-09 03:00:23 +0000
commit083bb80a125a5f61c07000e73d0ddb19dd248978 (patch)
treee604cebe3c1701bf853cce34fd60d6703db39220 /MdePkg/Library/StackCheckLibNull/StackCheckLibNullMsvc.c
parent8ed11b21e54417a450c64914a3898ce75c243c7f (diff)
openssl: Fix multiple vulnerabilities
This is a rollup commit from upstream to fix: Reject oversized inputs in ASN1_mbstring_ncopy() cms: kek_unwrap_key: Fix out-of-bounds read in check-byte validation cms: kek_unwrap_key: test for fix out-of-bounds read in check-byte validation Avoid length truncation in ASN1_STRING_set pkcs12: verify that the pbmac1 key length is safe Reject potentially forged encrypted CMS AuthEnvelopedData messages QUIC stack must limit the number of PATH_CHALLENGE frames processed in RX Fix NULL dereference in QUIC address validation Fix potential NULL dereference processing CMS PasswordRecipientInfo Fix potential NULL dereference in OSSL_CRMF_ENCRYPTEDVALUE_decrypt() Enforce implicit rejection for CMS/PKCS#7 decryption Use the correct issuer when validating rootCAKeyUpdate Match the local q DHX parameter against the peer's q Apply the buffered IV on the AES-OCB EVP_Cipher() path Fix handling of empty-ciphertext messages in AES-GCM-SIV and AES-SIV Fix possible use-after-free in OpenSSL PKCS7_verify() Approved by: re (cperciva) Approved by: so Obtained from: OpenSSL Security: FreeBSD-SA-26:35.openssl Security: CVE-2026-7383 Security: CVE-2026-9076 Security: CVE-2026-34180 Security: CVE-2026-34181 Security: CVE-2026-34182 Security: CVE-2026-34183 Security: CVE-2026-42764 Security: CVE-2026-42766 Security: CVE-2026-42767 Security: CVE-2026-42768 Security: CVE-2026-42769 Security: CVE-2026-42770 Security: CVE-2026-45445 Security: CVE-2026-45446 Security: CVE-2026-45447
Diffstat (limited to 'MdePkg/Library/StackCheckLibNull/StackCheckLibNullMsvc.c')
0 files changed, 0 insertions, 0 deletions