[HN Gopher] Withdrawal of OpenSSL 3.0.6 and 1.1.1r
       ___________________________________________________________________
        
       Withdrawal of OpenSSL 3.0.6 and 1.1.1r
        
       Author : TimWolla
       Score  : 101 points
       Date   : 2022-10-12 14:37 UTC (8 hours ago)
        
 (HTM) web link (mta.openssl.org)
 (TXT) w3m dump (mta.openssl.org)
        
       | Felger wrote:
       | Good news. I observed those AES cipher/lz2-v2 issues with dead
       | tunnels on newer builds of OpenVPN, on i5-8265u CPU but not on R5
       | 3600. Had to rollback on a previous release.
        
       | jiripospisil wrote:
       | Vote to stop shipping 3.0.6 and 1.1.1r
       | (https://github.com/openssl/general-policies/pull/32)
       | 
       | - Regression: X509_sign, etc., no longer implicitly refresh the
       | cached TBSCertificate
       | (https://github.com/openssl/openssl/issues/19388)
       | 
       | - PKCS12_parse leaves errors on stack [3.0.6]
       | (https://github.com/openssl/openssl/issues/19389)
        
       | TillE wrote:
       | Another W for my habit of not upgrading our application's
       | embedded OpenSSL library until there's an actual relevant
       | security bug fix.
       | 
       | We also dodged the serious bug introduced in 3.0.4 that way.
        
       | bumblebritches5 wrote:
        
       | bombcar wrote:
       | 3.0.6 was released 3 days ago:
       | https://mta.openssl.org/pipermail/openssl-announce/2022-Octo...
       | and apparently had "Fix for custom ciphers to prevent accidental
       | use of NULL encryption ([CVE-2022-3358])"
       | 
       | https://www.openssl.org/news/vulnerabilities.html#CVE-2022-3...
       | 
       | 1.1.1r was "Added a missing header for memcmp that caused
       | compilation failure on some platforms"
        
         | oittaa wrote:
         | Did these changes cause performance issues? The original post
         | doesn't really explain what the main problem was.
        
           | bombcar wrote:
           | No idea, but a "non security regression" almost always has to
           | be performance with OpenSSL, I'd think.
           | 
           | Or it stopped building on some platform.
        
         | Denvercoder9 wrote:
         | Those are just the only cited major changes, not the only
         | changes in those releases. See the full changelogs:
         | 
         | - 3.0.6: https://www.openssl.org/news/cl30.txt
         | 
         | - 1.1.1r: https://www.openssl.org/news/cl111.txt
        
       ___________________________________________________________________
       (page generated 2022-10-12 23:02 UTC)