diff options
author | Xi Ruoyao <xry111@xry111.site> | 2022-06-23 12:23:06 +0800 |
---|---|---|
committer | Xi Ruoyao <xry111@xry111.site> | 2022-06-23 12:23:06 +0800 |
commit | 0b0fa07cd497c31d24c64359e50d65641986b81f (patch) | |
tree | 2ffe8e60e263f51791433d6e64f0534406945bbe /chapter08/libffi.xml | |
parent | e909a1ebdf37d817f53707c5a998a6786d5af1cd (diff) |
openssl: mark c_rehash obsolete
The c_rehash script, shipped by OpenSSL versions in current LFS trunk
and all previous LFS releases, is vulnerable to CVE-2022-2068. It's
fixed in 3.0.4, but OpenSSL 3.0.4 is completely broken on CPU models with
AVX-512 extension [1]. So we'd like to defer OpenSSL update and wait for
upstream consensus about "would 3.0.5 be released in urgency".
But, the upstream has announced that use of c_rehash is obsolete now [2].
So we can tell people not to use it.
[1]: https://github.com/openssl/openssl/issues/18625
[2]: https://www.openssl.org/news/secadv/20220621.txt
Diffstat (limited to 'chapter08/libffi.xml')
0 files changed, 0 insertions, 0 deletions