[openwrt/openwrt] mbedtls: update to 3.6.4

LEDE Commits lede-commits at lists.infradead.org
Thu Jul 10 11:51:03 PDT 2025


hauke pushed a commit to openwrt/openwrt.git, branch openwrt-24.10:
https://git.openwrt.org/49fdb75c7b9c3d66b87375185d2e4e725474032e

commit 49fdb75c7b9c3d66b87375185d2e4e725474032e
Author: Antony Kolitsos <zeusomighty at hotmail.com>
AuthorDate: Thu Jul 3 17:17:00 2025 -0700

    mbedtls: update to 3.6.4
    
    This release includes fixes for security issues.
    
    Mbed TLS 3.6 is a long-term support (LTS) branch. It will be supported with bug-fixes and security fixes until at least March 2027.
    
    Security Advisories
    
    For full details, please see the following links:
    
        Race condition in AESNI support detection [1]
        Heap buffer under-read when parsing PEM-encrypted material [2]
        Unchecked return value in LMS verification allows signature bypass [3]
        Out-of-bounds read in mbedtls_lms_import_public_key() [4]
        Timing side-channel in block cipher decryption with PKCS#7 padding [5]
        NULL pointer dereference after using mbedtls_asn1_store_named_data() [6]
        Misleading memory management in mbedtls_x509_string_to_names() [7]
    
    [1] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-1/
    [2] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-2/
    [3] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-3/
    [4] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-4/
    [5] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-5/
    [6] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-6/
    [7] https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-06-7/
    
    Signed-off-by: Antony Kolitsos <zeusomighty at hotmail.com>
    Link: https://github.com/openwrt/openwrt/pull/19291
    Signed-off-by: Robert Marko <robimarko at gmail.com>
    (cherry picked from commit 2c8a433cd2c4f0cd4049e5b0fa147c824ec27c62)
    Link: https://github.com/openwrt/openwrt/pull/19324
    Signed-off-by: Hauke Mehrtens <hauke at hauke-m.de>
---
 package/libs/mbedtls/Makefile | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/package/libs/mbedtls/Makefile b/package/libs/mbedtls/Makefile
index 6d16819d3a..d6dfd6b68f 100644
--- a/package/libs/mbedtls/Makefile
+++ b/package/libs/mbedtls/Makefile
@@ -8,13 +8,13 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=mbedtls
-PKG_VERSION:=3.6.3
+PKG_VERSION:=3.6.4
 PKG_RELEASE:=1
 PKG_BUILD_FLAGS:=no-mips16 gc-sections no-lto
 
 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.bz2
 PKG_SOURCE_URL=https://github.com/Mbed-TLS/$(PKG_NAME)/releases/download/$(PKG_NAME)-$(PKG_VERSION)
-PKG_HASH:=64cd73842cdc05e101172f7b437c65e7312e476206e1dbfd644433d11bc56327
+PKG_HASH:=ec35b18a6c593cf98c3e30db8b98ff93e8940a8c4e690e66b41dfc011d678110
 
 PKG_LICENSE:=GPL-2.0-or-later
 PKG_LICENSE_FILES:=LICENSE




More information about the lede-commits mailing list