pkgsrc-WIP-changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
libreswan: upgrade 5.3.2 -> 5.4.1
Module Name: pkgsrc-wip
Committed By: Andrew Cagney <andrew.cagney%gmail.com@localhost>
Pushed By: cagney
Date: Wed Oct 7 15:02:14 2026 +0000
Changeset: 0cff3f8937f519391cf1795c77d34de36bc31998
Modified Files:
libreswan/Makefile
libreswan/TODO
libreswan/distinfo
Log Message:
libreswan: upgrade 5.3.2 -> 5.4.1
v5.4.1 (Oct 5, 2026)
* Security
- fix CVE-2026-77206 - NPE - unexpected-eap-packet
http://libreswan.org/security/CVE-2026-77206
[Claude and Ada Logics, David Korczynski, Andrew]
- fix CVE-2026-77207 - NPE - empty-pkcs7-payload
http://libreswan.org/security/CVE-2026-77207
[Claude and Ada Logics, David Korczynski, Andrew]
- fix CVE-2026-94453 - UAF - EOF in IKETCP
http://libreswan.org/security/CVE-2026-94453
[Vlad Miu, Andrew]
- disable dns-match-id,=, - UAF [#3071 Vlad Miu, Andrew]
* Linux:
- allow connect(ADDR/UDP/0) [#3042 Tuomo, Antony, Andrew]
* Testing:
- add test for CVE-2026-77205 - DOS - fips-cert-leak
http://libreswan.org/security/CVE-2026-77205
[Wojciech Tatarski (TuxCare), Andrew]
* Building
- fix NetBSD 11.0
v5.4 (August 13, 2026)
* Security
- add __counted_by__() attribute to buffers [Andrew]
* IKEv2:
- update IKE_INTERMEDIATE exchange to RFC 9370 [Daiki Ueno, Ruiliio, Andrew]
- implement IKE_ADDITIONAL_KE for RFC 9370 [Daiki]
- support ML_KEM_768 in IKE_SA_INIT and IKE_INTERMEDIATE exchanges [Andrew, Daiki]
+ requires NSS >= 3.118.1
- support for IKE_FOLLOWUP_KE for RFC 9370 [Daiki #2958 #2918]
- treat broken IKE_AUTH Child SA response as INVALID_SYNTAX [mamtagambhir #2348]
- include DIGSIG algorithm in IKE_AUTH request log [Amrinder Singh #2490 #2627]
- clarify missing Child SA log during delete [Osema Fadhel #1585 #2695]
- include proposed traffic selectors in initiator logs [Osema Fadhel #2660 #2534]
- fix triple log of "no proposal chosen" [Shubham Kumar #2740 #1604]
- clearly log whenmessage is re-assembled [Sabari07 #2716 #2450]
- fix crash when deleting larval connection [Ondrej, Ilya Maximets, Andrew, #2647]
* X.509 and crypto:
- fix loop when crlcheckinterval=0+`ipsec fetchcrls` [Wofferl #2383]
- log default crypto policy during startup [Vinayak Sandur #2759 #2753]
* Kernel:
- fix host-to-host on FreeBSD, NetBSD, OpenBSD [Amrinder Singh]
- optimize acquire by adding msgid [Vinayak Sandur]
- fix on-demand on FreeBSD, NetBSD, OpenBSD [Amrinder Singh]
- fix metrics on Linux VTI interfaces [Cleberson Batista, Andrew #2601]
- include selectors in Linux policy error logs [Amrinder Singh #1544 #2651]
- include XFRM message name in Linux errors [Anish #2701 #2653]
- drop redundant "SPI" from kernel logs [Sabari07 #2694 #2654]
- be sensitive when logging kernel SPIs [shahrinf #2652 #2670]
* config (ipsec.conf, ipsec pluto --...):
- fix plutodebug=all,add-prefix [Andrew #2338]
- fix per-connection debug= option (experimental in v5.0) [Andrew]
- support dns-resolver=systemd [Amirreza #2379 #2356 #2376, Andrew]
- better errors when invalid auto=, phase2=, and sendca= [Amrinder Singh #2625 #2492]
- fix config dump missing values [Mohana Katari #2630]
- fix --stderrlog overriding ipsec.conf [Vinayak Sandur #2599]
- fix --seedbits and --seeddev overrides [[ANISH-SR #2718 #2707]
- enable leak-detective by default [ANISH-SR #2743 #2725]
- support `ipsec addconn --configsetup=exampledir` [Shubham Kumar #2717 #2742]
- add warnings when IKEv2 config contains xauth params [Osema Fadhel #2738 #2018]
- fix ignore-peer-dns= [Amrinder Singh #2539 #2636]
- add loglimit=no to disable rate limiting [Shubham Kumar #2741 #2713]
- prefer negotationshunt=drop over hold [Amrinder Singh #2649 #2191]
- update proposal parser [Vinayak Sandur #2744 #2737]
+ warn when ike=ENCR-INTEG-PRF-DH
+ allow unambigious ike=ENCR-PRF-INTEG-DH
- support updown-config={async,exec} (experimental) [Andrew]
- support leftaddresspool=2025::/56/64 for leasing subnets (experimental) [Andrew]
- fix display of ike-socket-errqueue= [Vinayak Sandur #2650 #2548]
* logging:
- rate limit logging of bogus UDP packets [Sabari07 #2727 #2727]
- use IP%interface syntax when logging interface addresses [Nour Mustapha #2554 #2642]
- be consistent with pluto's startup logs ([disabled]) [Amrinder Singh #2747 #2745]
- fix count of dropped packets [André Luiz Rodrigues Castro da Nóbrega #2696 #2546]
- remove internal names from `ipsec status` state output [Fatma #2645 #1670]
- remove redundant "leak-detective enabled" logs [Amrinder Singh #2739 #2735]
* building:
- on Linux, prefer system's xfrm.h [Andrew, Antony, Vukasink, #2431 #2396 #2501]
Note: old Linux distros may need USE_XFRM_HEADER_COPY=true
- fix RPM package file/directory ownership [Joseph Marreo Corchado, Tuomo, #2167]
- fix seccomp rules to work with Bash 5.3 [Maciej S. Szmigiero, #2371]
- fix Debian based OS when no EDDSA [Andrew, shahrinf, #2659]
- remove HAVE_BROKEN_POPEN=true needed by Angstrom linux [Andrew, #2588]
Angstrom's last release was 2017 or 8 years ago
- on Linux, except OpenWRT and Alpine, default to INITSYSTEM=systemd [Andrew]
- GCC 16 fixes [Daiki Ueno #2598]
- fix `make git-rpm` [Ondrej Moris #2512]
- build with FORTIFY_SOURCE=3 [Andrew #2782]
- On FreeBSD, build using CLANG [Andrew]
- add/use COUNTED_BY(len) on open array structures [Andrew]
- add/use COUNTED_BY_PTR(len) on dynamic arrays when CLANG [Andrew]
- support packaging on Amazon Linux [Patric Kerpan]
* testing:
- increase expiration on PKI keys to 1 month [islem52 #2726 #2720]
- Alpine test domain upgraded to 3.22.2 [Andrew]
- Debian test domain upgraded to 12.13 [Andrew]
- Fedora test domain upgraded to f43 [Andrew]
- FreeBSD test domain upgraded to 14.4 [Andrew, Ueno #2341]
- OpenBSD test domain upgraded to 7.8 [Andrew]
* documentation:
- fix typos in example config files [Mohana Katari #2632]
- document exampledir=, loglimit= [Shubham Kumar]
- update negotiationshunt= [Amrinder Singh]
- cleanup OE example config files [Navid Fayezi #2648]
- document reject-simultaneous-ike-auth [Ondrej Moris]
- clarify sendifasked= [Daiki Ueno]
- document authby=eddsa [Rishabh]
To see a diff of this commit:
https://wip.pkgsrc.org/cgi-bin/gitweb.cgi?p=pkgsrc-wip.git;a=commitdiff;h=0cff3f8937f519391cf1795c77d34de36bc31998
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
diffstat:
libreswan/Makefile | 2 +-
libreswan/TODO | 6 ++++++
libreswan/distinfo | 6 +++---
3 files changed, 10 insertions(+), 4 deletions(-)
diffs:
diff --git a/libreswan/Makefile b/libreswan/Makefile
index c6eef38da8..9d54e67e8a 100644
--- a/libreswan/Makefile
+++ b/libreswan/Makefile
@@ -15,7 +15,7 @@
#
# libreswan: 5.0 5.0nb1 ...
-DISTNAME= libreswan-5.3.2
+DISTNAME= libreswan-5.4.1
MASTER_SITES= https://download.libreswan.org/
CATEGORIES= security
diff --git a/libreswan/TODO b/libreswan/TODO
index 0ba2bf4426..62ae684e30 100644
--- a/libreswan/TODO
+++ b/libreswan/TODO
@@ -7,6 +7,12 @@
- add following entries to pkg-vulnerabilities
+libreswan<5.4.1 denial-of-service https://libreswan.org/security/CVE-2026-77206/CVE-2026-77206.txt
+libreswan<5.4.1 denial-of-service https://libreswan.org/security/CVE-2026-77207/CVE-2026-77207.txt
+libreswan<5.4.1 use-after-free https://libreswan.org/security/CVE-2026-94453/CVE-2026-94453.txt
+
+libreswan<5.3.3 denial-of-service https://libreswan.org/security/CVE-2026-77205/CVE-2026-77205.txt
+
libreswan<5.3.2 denial-of-service https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt
libreswan<5.3.1 denial-of-service https://libreswan.org/security/CVE-2026-12413/CVE-2026-12413.txt
libreswan<5.3.1 denial-of-service https://libreswan.org/security/CVE-2026-50721/CVE-2026-50721.txt
diff --git a/libreswan/distinfo b/libreswan/distinfo
index 9756bb9839..dd8e1eadbd 100644
--- a/libreswan/distinfo
+++ b/libreswan/distinfo
@@ -1,5 +1,5 @@
$NetBSD$
-BLAKE2s (libreswan-5.3.2.tar.gz) = ec4e3568530eb6d293b0088ee1c7cf4a4a9b84a3bfb3b5f459ba936f3c6a9612
-SHA512 (libreswan-5.3.2.tar.gz) = 4dfe71bed06d356c5a33e1874ec934eab8a57a2bdedff8069ebcf65b09dd79490665cbb5b94b691d6e873a0a8e6eb131a4942ffa845a5836a5344436c8efb879
-Size (libreswan-5.3.2.tar.gz) = 4223489 bytes
+BLAKE2s (libreswan-5.4.1.tar.gz) = cd8c3721aacffd498a16dd5b3fa42ffbeec9db6605082804f861b831b1768bd8
+SHA512 (libreswan-5.4.1.tar.gz) = e9f97da181d609889290de5b72e446b0193dbfc963859fe0303671bdef17755ba77478b82a4176f95ddc57df4a62b517d6ff5414b47bb2ccfb6f1ff626f33759
+Size (libreswan-5.4.1.tar.gz) = 4359418 bytes
Home |
Main Index |
Thread Index |
Old Index