Go to file
Fabrice Fontaine c4658ede71 package/wolfssl: security bump to version 5.6.4
[Medium] A fix was added, but still under review for completeness, for a
Bleichenbacher style attack, leading to being able to decrypt a saved
TLS connection and potentially forge a signature after probing with a
large number of trial connections. This issue is around RSA decryption
and affects static RSA cipher suites on the server side, which are not
recommended to be used and are off by default. Static RSA cipher suites
were also removed from the TLS 1.3 protocol and only present in TLS 1.2
and lower. All padding versions of RSA decrypt are affected since the
code under review is outside of the padding processing. Information
about the private keys is NOT compromised in affected code. It's
recommended to disable static RSA cipher suites and update the version
of wolfSSL used if using RSA private decryption alone outside of TLS.

https://github.com/wolfSSL/wolfssl/releases/tag/v5.6.4-stable

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2023-10-31 19:02:57 +01:00
arch arch/powerpc: drop ABI selection 2023-08-20 23:22:27 +02:00
board configs/sipeed_licheepi_nano: new board 2023-10-29 19:43:29 +01:00
boot boot/at91bootstrap: disable PIE and stack-protector build flags 2023-10-01 11:02:03 +02:00
configs configs/licheepi_zero: rename with manufacturer prefix 2023-10-29 19:50:07 +01:00
docs docs/manual: fix typo 2023-10-21 23:30:27 +02:00
fs fs/cpio: allow users to provide their own dracut modules 2023-02-06 22:46:35 +01:00
linux {linux, linux-headers}: bump 4.{14, 19}.x / 5.{4, 10, 15}.x / 6.{1, 5}.x series 2023-10-29 09:32:40 +01:00
package package/wolfssl: security bump to version 5.6.4 2023-10-31 19:02:57 +01:00
support Update for 2023.08.2 2023-10-16 11:34:39 +02:00
system package/skeleton-init-systemd: add option to use overlayfs on /var 2023-10-08 20:12:01 +02:00
toolchain package/gcc/gcc-final: add a target variant in charge of target installation 2023-09-30 14:49:51 +02:00
utils utils/getdeveloperlib.py: handle file removal 2023-09-11 22:08:22 +02:00
.checkpackageignore package/zchunk: security bump to version 1.3.2 2023-10-28 22:49:02 +02:00
.clang-format
.defconfig
.flake8
.gitignore
.gitlab-ci.yml support/misc/gitlab-ci.yml.in: retry a job only if it failed due to a runner issue 2023-08-27 10:09:37 +02:00
.shellcheckrc
CHANGES Update for 2023.02.6 2023-10-16 11:46:01 +02:00
Config.in Config.in: default to HTTPS for s.b.n backup site 2023-10-28 21:30:18 +02:00
Config.in.legacy package/linux-headers: drop 6.4.x option 2023-09-27 21:06:30 +02:00
COPYING
DEVELOPERS DEVELOPPERS: fix licheepi entries 2023-10-29 22:03:38 +01:00
Makefile package/pkg-utils: teach per-package-rsync to copy or hardlink dest 2023-10-21 21:18:13 +02:00
Makefile.legacy
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on OFTC IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches