summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSam James <sam@gentoo.org>2022-06-30 19:31:38 +0000
committerSam James <sam@gentoo.org>2022-06-30 19:32:45 +0000
commit82e7edabadc776d7b123ee7bfd65a78a892eae47 (patch)
tree0e532d8f854bf2919b9700834f0fe5e7d8ba78ee /profiles
parentdev-libs/openssl: add 3.0.4 (diff)
downloadgentoo-82e7edabadc776d7b123ee7bfd65a78a892eae47.tar.gz
gentoo-82e7edabadc776d7b123ee7bfd65a78a892eae47.tar.bz2
gentoo-82e7edabadc776d7b123ee7bfd65a78a892eae47.zip
dev-libs/openssl: backport AVX512 overflow fix
Bug: https://github.com/openssl/openssl/issues/18625 Signed-off-by: Sam James <sam@gentoo.org>
Diffstat (limited to 'profiles')
-rw-r--r--profiles/package.mask7
1 files changed, 0 insertions, 7 deletions
diff --git a/profiles/package.mask b/profiles/package.mask
index e9663afb0ce2..4c5d63309305 100644
--- a/profiles/package.mask
+++ b/profiles/package.mask
@@ -44,13 +44,6 @@
# as deprecated since March 2022. Removal in 30 days (Bug #855299).
gnome-extra/gtkhtml
-# Sam James <sam@gentoo.org> (2022-06-29)
-# Pre-emptively mask broken upstream versions.
-# openssl 3.0.4 has a buffer overflow w/ AVX512 (https://github.com/openssl/openssl/issues/18625)
-# Gentoo isn't vulnerable to the original CVE which caused these releases
-# (CVE-2022-2068) as we have our own rehash script.
-=dev-libs/openssl-3.0.4
-
# Piotr Karbowski <slashbeast@gentoo.org> (2022-06-26)
# Abandoned upstream, depends on API that no longer exists.
# Removal on 2022-07-26.