Skip to content

Openssl 3.0.15 - #6160

Merged
mergify[bot] merged 3 commits into
tianocore:masterfrom
liyi77:openssl3.0.15
Sep 27, 2024
Merged

mergify[bot] merged 3 commits into
tianocore:masterfrom
liyi77:openssl3.0.15

Conversation

@liyi77

@liyi77 liyi77 commented Sep 4, 2024

Copy link
Copy Markdown
Contributor

Description

https://bugzilla.tianocore.org/show_bug.cgi?id=4842

  • Breaking change?
    • Breaking change - Does this PR cause a break in build or boot behavior?
    • Examples: Does it add a new library class or move a module to a different repo.
  • Impacts security?
  • Includes tests?
    • Tests - Does this PR include any explicit test code?
    • Examples: Unit tests or integration tests.

How This Was Tested

Unit test of CryptoPkg.

Integration Instructions

NA

@github-actions github-actions Bot added the impact:security This change has a direct security impact such as changing a crypto algorithm. label Sep 4, 2024
@liyi77

liyi77 commented Sep 4, 2024

Copy link
Copy Markdown
Contributor Author

Size impact between 3.0.9~3.0.15(no compressed):
No increase in Pei driver [Only AES, SHA, SM3]
65KB increase in FullDxe driver [All]

Comment thread CryptoPkg/Library/OpensslLib/OpensslGen/include/openssl/bio.h
@liyi77 liyi77 closed this Sep 19, 2024
@liyi77 liyi77 reopened this Sep 19, 2024
BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=4842

CVE-2024-6119 affects TLS-client implementation of EDK2. Fix it by
updating to 3.0.15.

Signed-off-by: Li Yi <yi1.li@intel.com>
@liyi77

liyi77 commented Sep 23, 2024

Copy link
Copy Markdown
Contributor Author

Hi @jyao1 , could you take a look?

@jyao1

jyao1 commented Sep 27, 2024

Copy link
Copy Markdown
Contributor

@liyi77 , would you please provide the compressed size difference?

@liyi77

liyi77 commented Sep 27, 2024

Copy link
Copy Markdown
Contributor Author

@liyi77 , would you please provide the compressed size difference?

there will be ~15KB increase after compressed.

@jyao1 jyao1 added the push Auto push patch series in PR if all checks pass label Sep 27, 2024
@mergify
mergify Bot merged commit 3ed4f43 into tianocore:master Sep 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

impact:security This change has a direct security impact such as changing a crypto algorithm. push Auto push patch series in PR if all checks pass

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants