immortalwrt/package
Eneas U de Queiroz a49a81a92f
wolfssl: bump to 5.2.0
Fixes two high-severity vulnerabilities:

- CVE-2022-25640: A TLS v1.3 server who requires mutual authentication
  can be bypassed.  If a malicious client does not send the
  certificate_verify message a client can connect without presenting a
  certificate even if the server requires one.

- CVE-2022-25638: A TLS v1.3 client attempting to authenticate a TLS
  v1.3 server can have its certificate heck bypassed. If the sig_algo in
  the certificate_verify message is different than the certificate
  message checking may be bypassed.

Signed-off-by: Eneas U de Queiroz <cotequeiroz@gmail.com>
(cherry picked from commit e89f3e85eb)
2022-04-14 01:05:20 +08:00
..
base-files base-files: sysupgrade: fixes not found error 2022-04-02 00:38:40 +08:00
boot x86: grub2: search for the "kernel" filesystem on all disks 2022-04-12 03:03:57 +08:00
devel gdb: The signal definitions of musl and gdb collide 2022-04-04 22:09:04 +08:00
emortal autocore: backport changes from master 2022-04-09 00:14:42 +08:00
firmware firmware: intel-microcode: update to 20220207 2022-04-11 22:45:36 +08:00
kernel gpio-button-hotplug: fix data race 2022-04-14 01:03:01 +08:00
libs wolfssl: bump to 5.2.0 2022-04-14 01:05:20 +08:00
network firewall: refresh patches 2022-04-06 23:51:19 +08:00
system iucode-tool: fix host-compile on macos and non-x86 linux 2022-04-11 22:44:14 +08:00
utils busybox: Fix snprintf arguments in lock 2022-04-04 17:18:55 +08:00
Makefile build: fix opkg install step for large package selection 2021-05-12 23:27:23 +08:00