pkgsrc-WIP-changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

libreswan: upgrade 5.3.2 -> 5.4.1



Module Name:	pkgsrc-wip
Committed By:	Andrew Cagney <andrew.cagney%gmail.com@localhost>
Pushed By:	cagney
Date:		Wed Oct 7 15:02:14 2026 +0000
Changeset:	0cff3f8937f519391cf1795c77d34de36bc31998

Modified Files:
	libreswan/Makefile
	libreswan/TODO
	libreswan/distinfo

Log Message:
libreswan: upgrade 5.3.2 -> 5.4.1

v5.4.1 (Oct 5, 2026)
* Security
  - fix CVE-2026-77206 - NPE - unexpected-eap-packet
    http://libreswan.org/security/CVE-2026-77206
    [Claude and Ada Logics, David Korczynski, Andrew]
  - fix CVE-2026-77207 - NPE - empty-pkcs7-payload
    http://libreswan.org/security/CVE-2026-77207
    [Claude and Ada Logics, David Korczynski, Andrew]
  - fix CVE-2026-94453 - UAF - EOF in IKETCP
    http://libreswan.org/security/CVE-2026-94453
    [Vlad Miu, Andrew]
  - disable dns-match-id,=, - UAF [#3071 Vlad Miu, Andrew]
* Linux:
  - allow connect(ADDR/UDP/0) [#3042 Tuomo, Antony, Andrew]
* Testing:
  - add test for CVE-2026-77205 - DOS - fips-cert-leak
    http://libreswan.org/security/CVE-2026-77205
    [Wojciech Tatarski (TuxCare), Andrew]
* Building
  - fix NetBSD 11.0

v5.4 (August 13, 2026)
* Security
  - add __counted_by__() attribute to buffers [Andrew]
* IKEv2:
  - update IKE_INTERMEDIATE exchange to RFC 9370 [Daiki Ueno, Ruiliio, Andrew]
  - implement IKE_ADDITIONAL_KE for RFC 9370 [Daiki]
  - support ML_KEM_768 in IKE_SA_INIT and IKE_INTERMEDIATE exchanges [Andrew, Daiki]
    + requires NSS >= 3.118.1
  - support for IKE_FOLLOWUP_KE for RFC 9370 [Daiki #2958 #2918]
  - treat broken IKE_AUTH Child SA response as INVALID_SYNTAX [mamtagambhir #2348]
  - include DIGSIG algorithm in IKE_AUTH request log [Amrinder Singh #2490 #2627]
  - clarify missing Child SA log during delete [Osema Fadhel #1585 #2695]
  - include proposed traffic selectors in initiator logs [Osema Fadhel #2660 #2534]
  - fix triple log of "no proposal chosen" [Shubham Kumar #2740 #1604]
  - clearly log whenmessage is re-assembled [Sabari07 #2716 #2450]
  - fix crash when deleting larval connection [Ondrej, Ilya Maximets, Andrew, #2647]
* X.509 and crypto:
  - fix loop when crlcheckinterval=0+`ipsec fetchcrls` [Wofferl #2383]
  - log default crypto policy during startup [Vinayak Sandur #2759 #2753]
* Kernel:
  - fix host-to-host on FreeBSD, NetBSD, OpenBSD [Amrinder Singh]
  - optimize acquire by adding msgid [Vinayak Sandur]
  - fix on-demand on FreeBSD, NetBSD, OpenBSD [Amrinder Singh]
  - fix metrics on Linux VTI interfaces [Cleberson Batista, Andrew #2601]
  - include selectors in Linux policy error logs [Amrinder Singh #1544 #2651]
  - include XFRM message name in Linux errors [Anish #2701 #2653]
  - drop redundant "SPI" from kernel logs [Sabari07 #2694 #2654]
  - be sensitive when logging kernel SPIs [shahrinf #2652 #2670]
* config (ipsec.conf, ipsec pluto --...):
  - fix plutodebug=all,add-prefix [Andrew #2338]
  - fix per-connection debug= option (experimental in v5.0) [Andrew]
  - support dns-resolver=systemd [Amirreza #2379 #2356 #2376, Andrew]
  - better errors when invalid auto=, phase2=, and sendca= [Amrinder Singh #2625 #2492]
  - fix config dump missing values [Mohana Katari #2630]
  - fix --stderrlog overriding ipsec.conf [Vinayak Sandur #2599]
  - fix --seedbits and --seeddev overrides [[ANISH-SR #2718 #2707]
  - enable leak-detective by default [ANISH-SR #2743 #2725]
  - support `ipsec addconn --configsetup=exampledir` [Shubham Kumar #2717 #2742]
  - add warnings when IKEv2 config contains xauth params [Osema Fadhel #2738 #2018]
  - fix ignore-peer-dns= [Amrinder Singh #2539 #2636]
  - add loglimit=no to disable rate limiting [Shubham Kumar #2741 #2713]
  - prefer negotationshunt=drop over hold [Amrinder Singh #2649 #2191]
  - update proposal parser [Vinayak Sandur #2744 #2737]
    + warn when ike=ENCR-INTEG-PRF-DH
    + allow unambigious ike=ENCR-PRF-INTEG-DH
  - support updown-config={async,exec} (experimental) [Andrew]
  - support leftaddresspool=2025::/56/64 for leasing subnets (experimental) [Andrew]
  - fix display of ike-socket-errqueue= [Vinayak Sandur #2650 #2548]
* logging:
  - rate limit logging of bogus UDP packets [Sabari07 #2727 #2727]
  - use IP%interface syntax when logging interface addresses [Nour Mustapha #2554 #2642]
  - be consistent with pluto's startup logs ([disabled]) [Amrinder Singh #2747 #2745]
  - fix count of dropped packets [André Luiz Rodrigues Castro da Nóbrega #2696 #2546]
  - remove internal names from `ipsec status` state output [Fatma #2645 #1670]
  - remove redundant "leak-detective enabled" logs [Amrinder Singh #2739 #2735]
* building:
  - on Linux, prefer system's xfrm.h [Andrew, Antony, Vukasink, #2431 #2396 #2501]
    Note: old Linux distros may need USE_XFRM_HEADER_COPY=true
  - fix RPM package file/directory ownership [Joseph Marreo Corchado, Tuomo, #2167]
  - fix seccomp rules to work with Bash 5.3 [Maciej S. Szmigiero, #2371]
  - fix Debian based OS when no EDDSA [Andrew, shahrinf, #2659]
  - remove HAVE_BROKEN_POPEN=true needed by Angstrom linux [Andrew, #2588]
    Angstrom's last release was 2017 or 8 years ago
  - on Linux, except OpenWRT and Alpine, default to INITSYSTEM=systemd [Andrew]
  - GCC 16 fixes [Daiki Ueno #2598]
  - fix `make git-rpm` [Ondrej Moris #2512]
  - build with FORTIFY_SOURCE=3 [Andrew #2782]
  - On FreeBSD, build using CLANG [Andrew]
  - add/use COUNTED_BY(len) on open array structures [Andrew]
  - add/use COUNTED_BY_PTR(len) on dynamic arrays when CLANG [Andrew]
  - support packaging on Amazon Linux [Patric Kerpan]
* testing:
  - increase expiration on PKI keys to 1 month [islem52 #2726 #2720]
  - Alpine test domain upgraded to 3.22.2 [Andrew]
  - Debian test domain upgraded to 12.13 [Andrew]
  - Fedora test domain upgraded to f43 [Andrew]
  - FreeBSD test domain upgraded to 14.4 [Andrew, Ueno #2341]
  - OpenBSD test domain upgraded to 7.8 [Andrew]
* documentation:
  - fix typos in example config files [Mohana Katari #2632]
  - document exampledir=, loglimit= [Shubham Kumar]
  - update negotiationshunt= [Amrinder Singh]
  - cleanup OE example config files [Navid Fayezi #2648]
  - document reject-simultaneous-ike-auth [Ondrej Moris]
  - clarify sendifasked= [Daiki Ueno]
  - document authby=eddsa [Rishabh]

To see a diff of this commit:
https://wip.pkgsrc.org/cgi-bin/gitweb.cgi?p=pkgsrc-wip.git;a=commitdiff;h=0cff3f8937f519391cf1795c77d34de36bc31998

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

diffstat:
 libreswan/Makefile | 2 +-
 libreswan/TODO     | 6 ++++++
 libreswan/distinfo | 6 +++---
 3 files changed, 10 insertions(+), 4 deletions(-)

diffs:
diff --git a/libreswan/Makefile b/libreswan/Makefile
index c6eef38da8..9d54e67e8a 100644
--- a/libreswan/Makefile
+++ b/libreswan/Makefile
@@ -15,7 +15,7 @@
 #
 # libreswan: 5.0 5.0nb1 ...
 
-DISTNAME=	libreswan-5.3.2
+DISTNAME=	libreswan-5.4.1
 MASTER_SITES=   https://download.libreswan.org/
 
 CATEGORIES=	security
diff --git a/libreswan/TODO b/libreswan/TODO
index 0ba2bf4426..62ae684e30 100644
--- a/libreswan/TODO
+++ b/libreswan/TODO
@@ -7,6 +7,12 @@
 
 - add following entries to pkg-vulnerabilities
 
+libreswan<5.4.1		denial-of-service	https://libreswan.org/security/CVE-2026-77206/CVE-2026-77206.txt
+libreswan<5.4.1		denial-of-service	https://libreswan.org/security/CVE-2026-77207/CVE-2026-77207.txt
+libreswan<5.4.1		use-after-free		https://libreswan.org/security/CVE-2026-94453/CVE-2026-94453.txt
+
+libreswan<5.3.3		denial-of-service	https://libreswan.org/security/CVE-2026-77205/CVE-2026-77205.txt
+
 libreswan<5.3.2		denial-of-service	https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt
 libreswan<5.3.1		denial-of-service	https://libreswan.org/security/CVE-2026-12413/CVE-2026-12413.txt
 libreswan<5.3.1		denial-of-service	https://libreswan.org/security/CVE-2026-50721/CVE-2026-50721.txt
diff --git a/libreswan/distinfo b/libreswan/distinfo
index 9756bb9839..dd8e1eadbd 100644
--- a/libreswan/distinfo
+++ b/libreswan/distinfo
@@ -1,5 +1,5 @@
 $NetBSD$
 
-BLAKE2s (libreswan-5.3.2.tar.gz) = ec4e3568530eb6d293b0088ee1c7cf4a4a9b84a3bfb3b5f459ba936f3c6a9612
-SHA512 (libreswan-5.3.2.tar.gz) = 4dfe71bed06d356c5a33e1874ec934eab8a57a2bdedff8069ebcf65b09dd79490665cbb5b94b691d6e873a0a8e6eb131a4942ffa845a5836a5344436c8efb879
-Size (libreswan-5.3.2.tar.gz) = 4223489 bytes
+BLAKE2s (libreswan-5.4.1.tar.gz) = cd8c3721aacffd498a16dd5b3fa42ffbeec9db6605082804f861b831b1768bd8
+SHA512 (libreswan-5.4.1.tar.gz) = e9f97da181d609889290de5b72e446b0193dbfc963859fe0303671bdef17755ba77478b82a4176f95ddc57df4a62b517d6ff5414b47bb2ccfb6f1ff626f33759
+Size (libreswan-5.4.1.tar.gz) = 4359418 bytes


Home | Main Index | Thread Index | Old Index