Commit Graph

36 Commits

Author SHA1 Message Date
Daiki Ueno
e7c228512b pluto: ignore CREATE_CHILD_SA request if crypto is in progress
Resolves: RHEL-61461
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-11-12 14:28:06 +09:00
Daiki Ueno
d1c9c2a2c9 pluto: fix refcounting of whack FD at CREATE_CHILD_SA request
Resolves: RHEL-61461
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-11-12 14:27:13 +09:00
Daiki Ueno
656f1c566f Fix release number
Related: RHEL-51879
Related: RHEL-51881
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-08-06 16:14:09 +09:00
Daiki Ueno
1c8b8ac9e4 Make use of Netlink extack for additional error reporting
Resolves: RHEL-51881
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-08-06 13:47:48 +09:00
Daiki Ueno
cb1ffd261f Fix auto=ondemand connection initialization with TCP
Resolves: RHEL-51879
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-08-06 13:45:56 +09:00
Daiki Ueno
6040a43bc0 Update to 4.15
Resolves: RHEL-50006
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-07-30 23:22:36 +09:00
Daiki Ueno
5f7ba64f56 Bump release to synchronize with el9_5 package
Related: RHEL-32483
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-07-11 18:07:20 +09:00
Daiki Ueno
9d65c77b17 Fix CVE-2024-3652
Resolves: RHEL-32483
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-06-05 16:52:11 +09:00
Daiki Ueno
75c01c300b x509: unpack IPv6 general names based on length
Resolves: RHEL-32720
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-04-15 15:51:35 +09:00
Daiki Ueno
673a1e3414 Fix CVE-2024-2357
Resolves: RHEL-28743
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-04-11 10:37:37 +09:00
Daiki Ueno
ee24f10452 Update to 4.12 to fix CVE-2023-38710, CVE-2023-38711, CVE-2023-38712
Resolves: rhbz#2215956
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2023-08-09 16:41:06 +09:00
Sahana Prasad
90f8b5ec87 Just bumping up the version to include bugs for CVE-2023-2295. There is no
code fix for it. Fix for it is including the code fix for CVE-2023-30570.
Fix CVE-2023-2295 Regression of CVE-2023-30570 fixes in the•
Red Hat Enterprise Linux
Resolves: rhbz#2189777, rhbz#2190148

Signed-off-by: Sahana Prasad <sahana@redhat.com>
2023-05-05 12:51:51 +02:00
Sahana Prasad
f94145745f Just bumping up the version as an incorrect 9.3 build was created.
Related: rhbz#2187171

Signed-off-by: Sahana Prasad <sahana@redhat.com>
2023-05-04 17:27:53 +02:00
Sahana Prasad
07990296c4 Fix CVE-2023-30570:Malicious IKEv1 Aggressive Mode packets can crash
libreswan
Resolves: rhbz#2187171

Signed-off-by: Sahana Prasad <sahana@redhat.com>
2023-05-04 10:18:54 +02:00
Daiki Ueno
4d8f3bf2ac Fix CVE-2023-23009
Resolves: #2173674
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2023-04-04 10:45:59 +09:00
Daiki Ueno
28de992c74 Update to 4.9
Also switch to using %autopatch as in Fedora.

Resolves: #2128669
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2023-01-04 11:44:01 +09:00
Daiki Ueno
d36dffc2c8 Drop IKEv1 packets by default
Based on the Debian patch by Daniel Kahn Gillmor:
80fa99e9df

Resolves: #2039877
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2022-02-02 15:08:47 +01:00
Daiki Ueno
9dad4dab06 Rebuild to reflect gating.yaml change
Related: #2017355
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2022-01-17 16:53:59 +01:00
Daiki Ueno
b3fb8c34f4 gating.yaml: fix tier1 test case name
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2022-01-17 16:17:50 +01:00
Daiki Ueno
0a36b39687 Update to 4.6
Resolves: #2017355
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2022-01-17 15:13:23 +01:00
Daiki Ueno
7b891f3811 Update to 4.5
Resolves: #2017355
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2022-01-11 11:08:40 +01:00
Mohan Boddu
aac47aac46 Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Related: rhbz#1991688
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-08-09 21:41:46 +00:00
Stanislav Zidek
edb68a3169 add gating configuration 2021-07-25 11:41:43 +02:00
Daiki Ueno
e60042d1e1 Backport removal gethostbyname2 uses from the upstream
Also fix issues spotted by covscan

Related: rhbz#1975812
Resolves: rhbz#1938784
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2021-07-22 13:16:37 +02:00
Daiki Ueno
10cb60dea1 Rebuild with newer GCC to fix annocheck failures
Resolves: rhbz#1975812
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2021-07-13 13:34:35 +02:00
Daiki Ueno
f6017a5a18 Update to 4.4
Port compiler warning suppression by Paul Wouters:
8d7f98d414

Resolves: rhbz#1975812
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2021-07-01 16:33:50 +02:00
Daiki Ueno
71c8319aec Fix FTBFS with OpenSSL 3.0
Related: rhbz#1971065
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2021-06-24 18:20:34 +02:00
Mohan Boddu
d39cdc021d Rebuilt for RHEL 9 BETA for openssl 3.0
Related: rhbz#1971065
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-06-22 18:41:22 +00:00
Mohan Boddu
47b03063ca - Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-04-16 01:34:18 +00:00
DistroBaker
33ba4cfac8 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/libreswan.git#fdf40a922fca638095ac7dda5b8df75d296c967e
2021-02-06 07:23:36 +00:00
DistroBaker
902fc9ebcb Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/libreswan.git#7f24ffd5dc6ba18d72f58fbc7ce88259f66ce3d4
2020-12-20 01:24:35 +00:00
DistroBaker
0df7cd37f6 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/libreswan.git#d84dd699b8f4d899612de53778a4fa6261b2297e
2020-12-19 17:48:25 +00:00
DistroBaker
c88446b7f1 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/libreswan.git#ef86d999fc347c093f78881f0c7292be08bab840
2020-11-23 17:20:34 +00:00
DistroBaker
cbe282a134 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/libreswan.git#39fea3799fd2ff42f931fd14c75c9378db8edbf6
2020-10-27 21:19:29 +01:00
Petr Šabata
5389f58fcc RHEL 9.0.0 Alpha bootstrap
The content of this branch was automatically imported from Fedora ELN
with the following as its source:
https://src.fedoraproject.org/rpms/libreswan#edf019da096d996a265210d164af9c89a6b637c9
2020-10-15 17:26:36 +02:00
Release Configuration Management
17714fc5a8 New branch setup 2020-10-08 17:16:02 +00:00