From mboxrd@z Thu Jan 1 00:00:00 1970 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 From: =?utf-8?b?VG9tw6HFoSBNcsOheiA8dG1yYXpAZmVkb3JhcHJvamVjdC5vcmc+?= To: git-commits@fedoraproject.org Subject: [rpms/openssl] rebase_40beta: - fix CVE-2009-4355 - leak in applications incorrectly calling Date: Tue, 09 Jun 2026 12:42:03 GMT Message-ID: <178100892366.1.4866234679785496058.rpms-openssl-79249339a7ed@fedoraproject.org> List-ID: X-Git-Repo: rpms/openssl X-Git-Branch: rebase_40beta X-Git-Rev: 79249339a7ede8054be53d22ea30ef0c1afd68b8 ICAgICAgICAgICAgQSBuZXcgY29tbWl0IGhhcyBiZWVuIHB1c2hlZC4KCiAgICAgICAgICAgIFJl cG8gICA6IHJwbXMvb3BlbnNzbAogICAgICAgICAgICBCcmFuY2ggOiByZWJhc2VfNDBiZXRhCiAg ICAgICAgICAgIENvbW1pdCA6IDc5MjQ5MzM5YTdlZGU4MDU0YmU1M2QyMmVhMzBlZjBjMWFmZDY4 YjgKICAgICAgICAgICAgQXV0aG9yIDogVG9tw6HFoSBNcsOheiA8dG1yYXpAZmVkb3JhcHJvamVj dC5vcmc+CiAgICAgICAgICAgIERhdGUgICA6IDIwMTAtMDEtMTRUMDg6NTc6MzQrMDA6MDAKICAg ICAgICAgICAgU3RhdHMgIDogKzg4Ly0zIGluIDMgZmlsZShzKQogICAgICAgICAgICBVUkwgICAg OiBodHRwczovL3NyYy5mZWRvcmFwcm9qZWN0Lm9yZy9ycG1zL29wZW5zc2wvYy83OTI0OTMzOWE3 ZWRlODA1NGJlNTNkMjJlYTMwZWYwYzFhZmQ2OGI4P2JyYW5jaD1yZWJhc2VfNDBiZXRhCgogICAg ICAgICAgICBMb2c6CiAgICAgICAgICAgIC0gZml4IENWRS0yMDA5LTQzNTUgLSBsZWFrIGluIGFw cGxpY2F0aW9ucyBpbmNvcnJlY3RseSBjYWxsaW5nCiAgICBDUllQVE9fZnJlZV9hbGxfZXhfZGF0 YSgpIGJlZm9yZSBhcHBsaWNhdGlvbiBleGl0ICgjNTQ2NzA3KQotIHVwc3RyZWFtIGZpeCBmb3Ig ZnV0dXJlIFRMUyBwcm90b2NvbCB2ZXJzaW9uIGhhbmRsaW5nCgotLS0KZGlmZiAtLWdpdCBhL29w ZW5zc2wtMS4wLjAtYmV0YTQtY3ZlLTIwMDktNDM1NS5wYXRjaCBiL29wZW5zc2wtMS4wLjAtYmV0 YTQtY3ZlLTIwMDktNDM1NS5wYXRjaApuZXcgZmlsZSBtb2RlIDEwMDY0NAppbmRleCAwMDAwMDAw Li42MWYwY2Q2Ci0tLSAvZGV2L251bGwKKysrIGIvb3BlbnNzbC0xLjAuMC1iZXRhNC1jdmUtMjAw OS00MzU1LnBhdGNoCkBAIC0wLDAgKzEsNDkgQEAKK01vZGlmeSBjb21wcmVzc2lvbiBjb2RlIHNv IGl0IGZyZWVzIHVwIHN0cnVjdHVyZXMgd2l0aG91dCB1c2luZyB0aGUKK2V4X2RhdGEgY2FsbGJh Y2tzLiBUaGlzIHdvcmtzIGFyb3VuZCBhIHByb2JsZW0gd2hlcmUgc29tZSBhcHBsaWNhdGlvbnMK K2NhbGwgQ1JZUFRPX2ZyZWVfYWxsX2V4X2RhdGEoKSBiZWZvcmUgYXBwbGljYXRpb24gZXhpdCAo ZS5nLiB3aGVuCityZXN0YXJ0aW5nKSB0aGVuIHVzZSBjb21wcmVzc2lvbiAoZS5nLiBTU0wgd2l0 aCBjb21wcmVzc2lvbikgbGF0ZXIuCitUaGlzIHJlc3VsdHMgaW4gc2lnbmlmaWNhbnQgcGVyLWNv bm5lY3Rpb24gbWVtb3J5IGxlYWtzIGFuZAoraGFzIGNhdXNlZCBzb21lIHNlY3VyaXR5IGlzc3Vl cyBpbmNsdWRpbmcgQ1ZFLTIwMDgtMTY3OCBhbmQKK0NWRS0yMDA5LTQzNTUuCitbU3RldmUgSGVu c29uXQorZGlmZiAtdXAgb3BlbnNzbC0xLjAuMC1iZXRhNC9jcnlwdG8vY29tcC9jX3psaWIuYy5j b21wbGVhayBvcGVuc3NsLTEuMC4wLWJldGE0L2NyeXB0by9jb21wL2NfemxpYi5jCistLS0gb3Bl bnNzbC0xLjAuMC1iZXRhNC9jcnlwdG8vY29tcC9jX3psaWIuYy5jb21wbGVhawkyMDA4LTEyLTEz IDE4OjE5OjQwLjAwMDAwMDAwMCArMDEwMAorKysrIG9wZW5zc2wtMS4wLjAtYmV0YTQvY3J5cHRv L2NvbXAvY196bGliLmMJMjAxMC0wMS0xMyAyMjowNjoyMC4wMDAwMDAwMDAgKzAxMDAKK0BAIC0x MzYsMTUgKzEzNiw2IEBAIHN0cnVjdCB6bGliX3N0YXRlCisgCisgc3RhdGljIGludCB6bGliX3N0 YXRlZnVsX2V4X2lkeCA9IC0xOworIAorLXN0YXRpYyB2b2lkIHpsaWJfc3RhdGVmdWxfZnJlZV9l eF9kYXRhKHZvaWQgKm9iaiwgdm9pZCAqaXRlbSwKKy0JQ1JZUFRPX0VYX0RBVEEgKmFkLCBpbnQg aW5kLGxvbmcgYXJnbCwgdm9pZCAqYXJncCkKKy0JeworLQlzdHJ1Y3QgemxpYl9zdGF0ZSAqc3Rh dGUgPSAoc3RydWN0IHpsaWJfc3RhdGUgKilpdGVtOworLQlpbmZsYXRlRW5kKCZzdGF0ZS0+aXN0 cmVhbSk7CistCWRlZmxhdGVFbmQoJnN0YXRlLT5vc3RyZWFtKTsKKy0JT1BFTlNTTF9mcmVlKHN0 YXRlKTsKKy0JfQorLQorIHN0YXRpYyBpbnQgemxpYl9zdGF0ZWZ1bF9pbml0KENPTVBfQ1RYICpj dHgpCisgCXsKKyAJaW50IGVycjsKK0BAIC0xODgsNiArMTc5LDEyIEBAIHN0YXRpYyBpbnQgemxp Yl9zdGF0ZWZ1bF9pbml0KENPTVBfQ1RYICoKKyAKKyBzdGF0aWMgdm9pZCB6bGliX3N0YXRlZnVs X2ZpbmlzaChDT01QX0NUWCAqY3R4KQorIAl7CisrCXN0cnVjdCB6bGliX3N0YXRlICpzdGF0ZSA9 CisrCQkoc3RydWN0IHpsaWJfc3RhdGUgKilDUllQVE9fZ2V0X2V4X2RhdGEoJmN0eC0+ZXhfZGF0 YSwKKysJCQl6bGliX3N0YXRlZnVsX2V4X2lkeCk7CisrCWluZmxhdGVFbmQoJnN0YXRlLT5pc3Ry ZWFtKTsKKysJZGVmbGF0ZUVuZCgmc3RhdGUtPm9zdHJlYW0pOworKwlPUEVOU1NMX2ZyZWUoc3Rh dGUpOworIAlDUllQVE9fZnJlZV9leF9kYXRhKENSWVBUT19FWF9JTkRFWF9DT01QLGN0eCwmY3R4 LT5leF9kYXRhKTsKKyAJfQorIAorQEAgLTQwMiw3ICszOTksNyBAQCBDT01QX01FVEhPRCAqQ09N UF96bGliKHZvaWQpCisgCQkJaWYgKHpsaWJfc3RhdGVmdWxfZXhfaWR4ID09IC0xKQorIAkJCQl6 bGliX3N0YXRlZnVsX2V4X2lkeCA9CisgCQkJCQlDUllQVE9fZ2V0X2V4X25ld19pbmRleChDUllQ VE9fRVhfSU5ERVhfQ09NUCwKKy0JCQkJCQkwLE5VTEwsTlVMTCxOVUxMLHpsaWJfc3RhdGVmdWxf ZnJlZV9leF9kYXRhKTsKKysJCQkJCQkwLE5VTEwsTlVMTCxOVUxMLE5VTEwpOworIAkJCUNSWVBU T193X3VubG9jayhDUllQVE9fTE9DS19DT01QKTsKKyAJCQlpZiAoemxpYl9zdGF0ZWZ1bF9leF9p ZHggPT0gLTEpCisgCQkJCWdvdG8gZXJyOwoKZGlmZiAtLWdpdCBhL29wZW5zc2wtMS4wLjAtYmV0 YTQtdGxzdmVyLnBhdGNoIGIvb3BlbnNzbC0xLjAuMC1iZXRhNC10bHN2ZXIucGF0Y2gKbmV3IGZp bGUgbW9kZSAxMDA2NDQKaW5kZXggMDAwMDAwMC4uODgyODJmOQotLS0gL2Rldi9udWxsCisrKyBi L29wZW5zc2wtMS4wLjAtYmV0YTQtdGxzdmVyLnBhdGNoCkBAIC0wLDAgKzEsMjcgQEAKK0ZpeCBo YW5kbGluZyBvZiBmdXR1cmUgVExTIHZlcnNpb25zLgorZGlmZiAtdXAgb3BlbnNzbC0xLjAuMC1i ZXRhNC9zc2wvczIzX3NydnIuYy50bHN2ZXIgb3BlbnNzbC0xLjAuMC1iZXRhNC9zc2wvczIzX3Ny dnIuYworLS0tIG9wZW5zc2wtMS4wLjAtYmV0YTQvc3NsL3MyM19zcnZyLmMudGxzdmVyCTIwMTAt MDEtMTIgMjI6MjA6MTUuMDAwMDAwMDAwICswMTAwCisrKysgb3BlbnNzbC0xLjAuMC1iZXRhNC9z c2wvczIzX3NydnIuYwkyMDEwLTAxLTEzIDIyOjAyOjQ3LjAwMDAwMDAwMCArMDEwMAorQEAgLTMx NSw3ICszMTUsNyBAQCBpbnQgc3NsMjNfZ2V0X2NsaWVudF9oZWxsbyhTU0wgKnMpCisgCQkJIChw WzFdID09IFNTTDNfVkVSU0lPTl9NQUpPUikgJiYKKyAJCQkgKHBbNV0gPT0gU1NMM19NVF9DTElF TlRfSEVMTE8pICYmCisgCQkJICgocFszXSA9PSAwICYmIHBbNF0gPCA1IC8qIHNpbGx5IHJlY29y ZCBsZW5ndGg/ICovKQorLQkJCQl8fCAocFs5XSA9PSBwWzFdKSkpCisrCQkJCXx8IChwWzldID49 IHBbMV0pKSkKKyAJCQl7CisgCQkJLyoKKyAJCQkgKiBTU0x2MyBvciB0bHMxIGhlYWRlcgorQEAg LTMzOSw2ICszMzksMTMgQEAgaW50IHNzbDIzX2dldF9jbGllbnRfaGVsbG8oU1NMICpzKQorIAkJ CQl2WzFdID0gVExTMV9WRVJTSU9OX01JTk9SOworICNlbmRpZgorIAkJCQl9CisrCQkJLyogaWYg bWFqb3IgdmVyc2lvbiBudW1iZXIgPiAzIHNldCBtaW5vciB0byBhIHZhbHVlCisrCQkJICogd2hp Y2ggd2lsbCB1c2UgdGhlIGhpZ2hlc3QgdmVyc2lvbiAzIHdlIHN1cHBvcnQuCisrCQkJICogSWYg VExTIDIuMCBldmVyIGFwcGVhcnMgd2Ugd2lsbCBuZWVkIHRvIHJldmlzZQorKwkJCSAqIHRoaXMu Li4uCisrCQkJICovCisrCQkJZWxzZSBpZiAocFs5XSA+IFNTTDNfVkVSU0lPTl9NQUpPUikKKysJ CQkJdlsxXT0weGZmOworIAkJCWVsc2UKKyAJCQkJdlsxXT1wWzEwXTsgLyogbWlub3IgdmVyc2lv biBhY2NvcmRpbmcgdG8gY2xpZW50X3ZlcnNpb24gKi8KKyAJCQlpZiAodlsxXSA+PSBUTFMxX1ZF UlNJT05fTUlOT1IpCgpkaWZmIC0tZ2l0IGEvb3BlbnNzbC5zcGVjIGIvb3BlbnNzbC5zcGVjCmlu ZGV4IDI3MjRiNWUuLjVhZmI3YTcgMTAwNjQ0Ci0tLSBhL29wZW5zc2wuc3BlYworKysgYi9vcGVu c3NsLnNwZWMKQEAgLTIzLDcgKzIzLDcgQEAKIFN1bW1hcnk6IEEgZ2VuZXJhbCBwdXJwb3NlIGNy eXB0b2dyYXBoeSBsaWJyYXJ5IHdpdGggVExTIGltcGxlbWVudGF0aW9uCiBOYW1lOiBvcGVuc3Ns CiBWZXJzaW9uOiAxLjAuMAotUmVsZWFzZTogMC4xOC4le2JldGF9JXs/ZGlzdH0KK1JlbGVhc2U6 IDAuMTkuJXtiZXRhfSV7P2Rpc3R9CiAjIFdlIHJlbW92ZSBjZXJ0YWluIHBhdGVudGVkIGFsZ29y aXRobXMgZnJvbSB0aGUgb3BlbnNzbCBzb3VyY2UgdGFyYmFsbAogIyB3aXRoIHRoZSBob2JibGUt b3BlbnNzbCBzY3JpcHQgd2hpY2ggaXMgaW5jbHVkZWQgYmVsb3cuCiBTb3VyY2U6IG9wZW5zc2wt JXt2ZXJzaW9ufS0le2JldGF9LXVzYS50YXIuYnoyCkBAIC03Myw2ICs3Myw4IEBAIFBhdGNoNjY6 IG9wZW5zc2wtMS4wLjAtYmV0YTQtYmFja3BvcnRzMi5wYXRjaAogUGF0Y2g2Nzogb3BlbnNzbC0x LjAuMC1iZXRhNC1yZW5lZy1zY3N2LnBhdGNoCiBQYXRjaDY4OiBvcGVuc3NsLTEuMC4wLWJldGE0 LXRscy1jb21wLnBhdGNoCiBQYXRjaDY5OiBvcGVuc3NsLTEuMC4wLWJldGE0LWFlc25pLnBhdGNo CitQYXRjaDcwOiBvcGVuc3NsLTEuMC4wLWJldGE0LXRsc3Zlci5wYXRjaAorUGF0Y2g3MTogb3Bl bnNzbC0xLjAuMC1iZXRhNC1jdmUtMjAwOS00MzU1LnBhdGNoCiAKIExpY2Vuc2U6IE9wZW5TU0wK IEdyb3VwOiBTeXN0ZW0gRW52aXJvbm1lbnQvTGlicmFyaWVzCkBAIC0xNjIsNiArMTY0LDggQEAg ZnJvbSBvdGhlciBmb3JtYXRzIHRvIHRoZSBmb3JtYXRzIHVzZWQgYnkgdGhlIE9wZW5TU0wgdG9v bGtpdC4KICVwYXRjaDY3IC1wMSAtYiAuc2NzdgogJXBhdGNoNjggLXAxIC1iIC50bHMtY29tcAog JXBhdGNoNjkgLXAxIC1iIC5hZXNuaQorJXBhdGNoNzAgLXAxIC1iIC50bHN2ZXIKKyVwYXRjaDcx IC1wMSAtYiAuY29tcGxlYWsKIAogIyBNb2RpZnkgdGhlIHZhcmlvdXMgcGVybCBzY3JpcHRzIHRv IHJlZmVyZW5jZSBwZXJsIGluIHRoZSByaWdodCBsb2NhdGlvbi4KIHBlcmwgdXRpbC9wZXJscGF0 aC5wbCBgZGlybmFtZSAle19fcGVybH1gCkBAIC00MTAsNiArNDE0LDExIEBAIHJtIC1yZiAkUlBN X0JVSUxEX1JPT1QvJXtfbGliZGlyfS9maXBzY2FuaXN0ZXIuKgogJXBvc3R1biAtcCAvc2Jpbi9s ZGNvbmZpZwogCiAlY2hhbmdlbG9nCisqIFRodSBKYW4gMTQgMjAxMCBUb21hcyBNcmF6IDx0bXJh ekByZWRoYXQuY29tPiAxLjAuMC0wLjE5LmJldGE0CistIGZpeCBDVkUtMjAwOS00MzU1IC0gbGVh ayBpbiBhcHBsaWNhdGlvbnMgaW5jb3JyZWN0bHkgY2FsbGluZworICBDUllQVE9fZnJlZV9hbGxf ZXhfZGF0YSgpIGJlZm9yZSBhcHBsaWNhdGlvbiBleGl0ICgjNTQ2NzA3KQorLSB1cHN0cmVhbSBm aXggZm9yIGZ1dHVyZSBUTFMgcHJvdG9jb2wgdmVyc2lvbiBoYW5kbGluZworCiAqIFdlZCBKYW4g MTMgMjAxMCBUb21hcyBNcmF6IDx0bXJhekByZWRoYXQuY29tPiAxLjAuMC0wLjE4LmJldGE0CiAt IGFkZCBzdXBwb3J0IGZvciBJbnRlbCBBRVMtTkkKIApAQCAtNTQzLDcgKzU1Miw3IEBAIHJtIC1y ZiAkUlBNX0JVSUxEX1JPT1QvJXtfbGliZGlyfS9maXBzY2FuaXN0ZXIuKgogLSB0ZW1wb3Jhcmls eSBwcm92aWRlIHN5bWxpbmsgdG8gb2xkIHNvbmFtZSB0byBtYWtlIGl0IHBvc3NpYmxlIHRvIHJl YnVpbGQKICAgdGhlIGRlcGVuZGVudCBwYWNrYWdlcyBpbiByYXdoaWRlCiAtIGFkZCBlYXAtZmFz dCBzdXBwb3J0ICgjNDI4MTgxKQotLSBhZGQgcG9zc2liaWxpdHkgdG8gZGlzYWJsZSB6bGliIGJ5 IHNldHRpbmcgCistIGFkZCBwb3NzaWJpbGl0eSB0byBkaXNhYmxlIHpsaWIgYnkgc2V0dGluZwog LSBhZGQgZmlwcyBtb2RlIHN1cHBvcnQgZm9yIHRlc3RpbmcgcHVycG9zZXMKIC0gZG8gbm90IG51 bGwgZGVyZWZlcmVuY2Ugb24gc29tZSBpbnZhbGlkIHNtaW1lIGZpbGVzCiAtIGFkZCBidWlsZHJl cXVpcmVzIHBrZ2NvbmZpZyAoIzQ3OTQ5MykKQEAgLTc1MCw3ICs3NTksNyBAQCBybSAtcmYgJFJQ TV9CVUlMRF9ST09ULyV7X2xpYmRpcn0vZmlwc2NhbmlzdGVyLioKIC0gdXBncmFkZSB0byBuZXcg dXBzdHJlYW0gdmVyc2lvbiAobm8gc29uYW1lIGJ1bXAgbmVlZGVkKQogLSBkaXNhYmxlIHRocmVh ZCB0ZXN0IC0gaXQgd2FzIHRlc3RpbmcgdGhlIGJhY2twb3J0IG9mIHRoZQogICBSU0EgYmxpbmRp bmcgLSBubyBsb25nZXIgbmVlZGVkCi0tIGFkZGVkIHN1cHBvcnQgZm9yIGNoYW5naW5nIHNlcmlh bCBudW1iZXIgdG8gCistIGFkZGVkIHN1cHBvcnQgZm9yIGNoYW5naW5nIHNlcmlhbCBudW1iZXIg dG8KICAgTWFrZWZpbGUuY2VydGlmaWNhdGUgKCMxNTExODgpCiAtIG1ha2UgY2EtYnVuZGxlLmNy dCBhIGNvbmZpZyBmaWxlICgjMTE4OTAzKQogCg==