Files
poky/meta/recipes-support
Peter Marko a4d31bb032 gnutls: upgrade 3.8.8 -> 3.8.9
Solves CVE-2024-12243

Refreshed patches

License-Update: multiple changes
* a8727cdb07
  COPYING.LESSER updated wording to latest FSF version
* 75f5ea8073
  LICENSE file merged to README.md
  COPYING and COPYING.LESSERv2 moved to top-level directory

Release notes: https://gitlab.com/gnutls/gnutls/-/blob/3.8.9/NEWS?ref_type=tags

* Version 3.8.9 (released 2025-02-07)

** libgnutls: leancrypto was added as an interim option for PQC
   The library can now be built with leancrypto instead of liboqs for
   post-quantum cryptography (PQC), when configured with
   --with-leancrypto option instead of --with-liboqs.

** libgnutls: Experimental support for ML-DSA signature algorithm
   The library and certtool now support ML-DSA signature algorithm as
   defined in FIPS 204 and based on
   draft-ietf-lamps-dilithium-certificates-04. This feature is
   currently marked as experimental and can only be enabled when
   compiled with --with-leancrypto or --with-liboqs.
   Contributed by David Dudas.

** libgnutls: Support for ML-KEM-1024 key encapsulation mechanism
   The support for ML-KEM post-quantum key encapsulation mechanisms
   has been extended to cover ML-KEM-1024, in addition to ML-KEM-768.
   MLKEM1024 is only offered as SecP384r1MLKEM1024 hybrid as per
   draft-kwiatkowski-tls-ecdhe-mlkem-03.

** libgnutls: Fix potential DoS in handling certificates with numerous name
   constraints, as a follow-up of CVE-2024-12133 in libtasn1. The
   bundled copy of libtasn1 has also been updated to the latest 4.20.0
   release to complete the fix.  Reported by Bing Shi (#1553).
   [GNUTLS-SA-2025-02-07, CVSS: medium] [CVE-2024-12243]

** API and ABI modifications:
GNUTLS_PK_MLDSA44: New enum member of gnutls_pk_algorithm_t
GNUTLS_PK_MLDSA65: New enum member of gnutls_pk_algorithm_t
GNUTLS_PK_MLDSA87: New enum member of gnutls_pk_algorithm_t
GNUTLS_SIGN_MLDSA44: New enum member of gnutls_sign_algorithm_t
GNUTLS_SIGN_MLDSA65: New enum member of gnutls_sign_algorithm_t
GNUTLS_SIGN_MLDSA87: New enum member of gnutls_sign_algorithm_t

(From OE-Core rev: 4313d931673dd86aaf590c68f7b1fa364d752740)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2025-02-18 22:53:45 +00:00
..
2025-01-10 11:10:00 +00:00
2025-02-18 11:56:03 +00:00
2025-02-05 12:49:55 +00:00
2024-02-03 22:08:26 +00:00
2024-10-11 12:17:02 +01:00
2024-07-16 11:25:29 +01:00
2024-04-04 14:05:03 +01:00
2025-02-18 12:04:03 +00:00
2025-02-18 22:53:45 +00:00
2025-02-18 22:53:44 +00:00
2024-11-22 16:53:37 +00:00
2022-04-14 09:47:00 +01:00
2025-01-03 10:51:27 +00:00
2024-08-09 22:33:38 +01:00
2025-02-05 12:49:55 +00:00
2025-02-18 22:53:44 +00:00
2025-01-10 11:26:29 +00:00
2025-01-03 10:51:27 +00:00
2024-08-28 09:14:27 +01:00
2023-06-28 07:56:33 +01:00
2022-12-22 23:05:50 +00:00
2024-11-18 22:09:02 +00:00
2024-10-11 12:17:02 +01:00
2024-01-24 15:46:19 +00:00
2025-02-05 12:49:55 +00:00
2024-05-28 09:38:23 +01:00
2024-08-23 22:43:27 +01:00
2024-08-28 09:14:26 +01:00
2024-08-29 21:58:19 +01:00
2025-02-10 13:03:58 +00:00
2025-01-03 10:51:27 +00:00
2024-11-18 22:09:02 +00:00
2024-11-27 14:58:48 +00:00
2024-11-18 22:09:02 +00:00
2024-08-28 09:14:27 +01:00
2024-07-16 11:25:29 +01:00
2022-11-22 12:26:46 +00:00
2024-12-18 11:11:55 +00:00
2024-06-25 11:50:58 +01:00
2025-02-18 22:53:44 +00:00
2024-12-12 12:52:39 +00:00
2024-09-04 12:38:44 +01:00
2024-12-05 17:07:10 +00:00
2025-02-18 11:56:03 +00:00
2025-01-03 10:51:27 +00:00