Upgrade openssl to 3.3.7#16518
Conversation
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
P1 — 0001-Replacing-deprecated-functions patch reversal: The rebased patch now removes SSLv3 NULL-return guards and reverts DTLS from DTLS_method() back to dtlsv1_method(). If 3.3.7 handles this internally, it's fine — but needs confirmation is it expected
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Month is missing from changelog
28800ff to
fee4bdf
Compare
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
LGTM , all review comments are now addressed.
This version bump (3.3.5 → 3.3.7) contains only security fixes and makes the package more maintainable by dropping 11 CVE patches that are now included upstream.
e0d46d7 to
642729c
Compare
|
Given that this is a core toolchain package, can we get a full build with toolchain build? |
|
Have you explicitly tested with this |
|
|
642729c to
e40c972
Compare
| Patch115: CVE-2026-31791.patch | ||
| Patch116: CVE-2026-31790.patch | ||
|
|
||
| patch100: CVE-2026-31791.patch |
There was a problem hiding this comment.
| patch100: CVE-2026-31791.patch | |
| Patch100: CVE-2026-31791.patch |
e40c972 to
562d08e
Compare
This reverts commit 4c95610.



Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
Upgrade openssl to 3.3.7
Change Log
Does this affect the toolchain?
YES
Associated issues
Links to CVEs
Test Methodology