openwrt-mirror/package
Antony Kolitsos 2c8a433cd2 mbedtls: update to 3.6.4
This release includes fixes for security issues.

Mbed TLS 3.6 is a long-term support (LTS) branch. It will be supported with bug-fixes and security fixes until at least March 2027.

Security Advisories

For full details, please see the following links:

    Race condition in AESNI support detection [1]
    Heap buffer under-read when parsing PEM-encrypted material [2]
    Unchecked return value in LMS verification allows signature bypass [3]
    Out-of-bounds read in mbedtls_lms_import_public_key() [4]
    Timing side-channel in block cipher decryption with PKCS#7 padding [5]
    NULL pointer dereference after using mbedtls_asn1_store_named_data() [6]
    Misleading memory management in mbedtls_x509_string_to_names() [7]

[1] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-1/
[2] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-2/
[3] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-3/
[4] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-4/
[5] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-5/
[6] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-6/
[7] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-7/

Signed-off-by: Antony Kolitsos <zeusomighty@hotmail.com>
Link: https://github.com/openwrt/openwrt/pull/19291
Signed-off-by: Robert Marko <robimarko@gmail.com>
2025-07-04 11:10:16 +02:00
..
base-files base-files: handle packages alternatives when apk removes packages 2025-06-23 09:39:12 +02:00
boot qualcommax: ipq50xx: Add support for Yuncore AX830 2025-06-30 14:04:31 +02:00
devel perf: disable slang support 2025-06-16 23:22:59 +02:00
firmware qualcommax: ipq50xx: Add support for Yuncore AX830 2025-06-30 14:04:31 +02:00
kernel kernel: allow seamless migration from I40EVF 2025-06-29 15:45:52 +02:00
libs mbedtls: update to 3.6.4 2025-07-04 11:10:16 +02:00
network wifi-scripts: ucode: fix invalid generated MAC address 2025-06-27 13:09:17 +02:00
system ubus: update to Git HEAD (2025-07-02) 2025-07-02 19:10:33 +02:00
utils usbgadget: add OS descriptors support 2025-07-04 09:50:24 +08:00
Makefile package: rework contents of package index.json 2025-06-11 16:55:31 +02:00