meta-openembedded/meta-networking/recipes-support
Wang Mingyu 351ac66213
openvpn: upgrade 2.6.15 -> 2.6.16
Code maintenance / Compat changes
---------------------------------
- adapt to new "encrypt-then-mac" cipher suites in OpenSSL 3.6.0 - these
  need special handling which we don't do, so the t_lpback self-test
  failed on them.  Exclude from list of allowed ciphers, as there is no
  strong reason today to make OpenVPN use these.
- fix various compile-time warnings

Documentation updates
---------------------
- fix outdated and non-HTTPS URLs throughout the tree (doxygen, warnings,
  manpage, ...)

Bugfixes
--------
- Fix memcmp check for the hmac verification in the 3way handshake.
  This bug renders the HMAC based protection against state exhaustion on
  receiving spoofed TLS handshake packets in the OpenVPN server inefficient.
  CVE: 2025-13086
- fix invalid pointer creation in tls_pre_decrypt() - technically this is
  a memory over-read issue, in practice, the compilers optimize it away
  so no negative effects could be observed.
- Windows: in the interactive service, fix the "undo DNS config" handling.
- Windows: in the interactive service, disallow using of "stdin" for the
  config file, unless the caller is authorized OpenVPN Administrator
- Windows: in the interactive service, change all netsh calls to use
  interface index and not interface name - sidesteps all possible attack
  avenues with special characters in interface names.
- Windows: in the interactive service, improve error handling in
  some "unlikely to happen" paths.
- auth plugin/script handling: properly check for errors in creation on
  $auth_failed_reason_file (arf).
- for incoming TCP connections, close-on-exec option was applied to
  the wrong socket fd, leaking socket FDs to child processes.
- sitnl: set close-on-exec flag on netlink socket
- ssl_mbedtls: fix missing perf_pop() call (optional performance profiling)

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-25 07:44:41 -08:00
..
aoetools *.patch: add Upstream-Status to all patches 2023-06-21 09:15:20 -07:00
arptables meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
bmon meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
bridge-utils meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
celt051 meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
chrony chrony: remove buildtime installation of /var/lib/chrony 2025-11-13 10:15:06 -08:00
cifs meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
cim-schema recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
curlpp meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
dnsmasq dnsmasq: upgrade 2.90 -> 2.91 2025-03-24 07:29:13 -07:00
dovecot dovecot: Fix service start error 2025-10-31 08:55:36 -07:00
drbd meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
dropwatch meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
esmtp *.patch: add Upstream-Status to all patches 2023-06-21 09:15:20 -07:00
ettercap ettercap: Add patch for CMake 4+ compatibility 2025-07-09 13:35:19 -07:00
fetchmail fetchmail: upgrade to 6.5.2 to fix build with gcc-15 2025-04-26 10:31:27 -07:00
fping fping: upgrade 5.3 -> 5.4 2025-09-04 10:28:22 -07:00
fwknop fwknop: Specify target locations of gpg and wget 2024-08-19 10:19:25 -07:00
geoip meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
htpdate
http-parser http-parser: fix SRC_URI branch 2025-11-08 06:53:05 -08:00
ifenslave meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
ifmetric *.patch: add Upstream-Status to all patches 2023-06-21 09:15:20 -07:00
iftop iftop: fix build with gcc-15 2025-03-21 11:07:33 -07:00
ipcalc meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
ipvsadm ipvsadm: Pass build environment cflags to compiler 2023-05-26 18:36:56 -07:00
libcpr libcpr: upgrade 1.12.0 -> 1.13.0 2025-11-18 08:23:43 -08:00
libesmtp meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
libexosip2 libexosip2: package binaries in a separate package 2023-11-22 16:39:50 -08:00
libldb libldb: Fix build with glibc 2.43 2025-11-10 20:31:55 -08:00
libmaxminddb
libmemcached libmemcached: ignore CVE-2023-27478 2024-12-20 19:47:56 -08:00
libosip2 libosip2: add recipe 2023-10-17 21:42:56 -07:00
libtalloc libtalloc: fix pytalloc package ordering 2025-11-10 07:50:05 -08:00
libtdb libtdb: upgrade 1.4.13 -> 1.4.14 2025-08-20 07:35:08 -07:00
libtevent libtevent: upgrade 0.17.0 -> 0.17.1 2025-08-20 07:35:09 -07:00
linux-atm linux-atm: Fix build with gcc-15 2025-04-26 10:31:27 -07:00
lksctp-tools lkcp-tools: Fix test_1_to_1_recvfrom ptest failure 2025-11-19 12:00:45 -08:00
lowpan-tools meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
macchanger *.patch: add Upstream-Status to all patches 2023-06-21 09:15:20 -07:00
mctp mctp: upgrade 2.1 -> 2.4 2025-10-29 21:02:54 -07:00
mdio-tools mdio-netlink and mdio-tools: Fix license file path 2025-06-25 06:44:52 -07:00
memcached memcached: upgrade 1.6.38 -> 1.6.39 2025-08-04 11:45:23 -07:00
mtr mtr: upgrade 0.95 -> 0.96 2025-07-15 23:54:15 -07:00
nbd nbd: Do not inherit systemd 2024-05-23 08:44:42 -07:00
nbdkit nbdkit: upgrade 1.45.12 -> 1.45.14 2025-11-18 08:23:43 -08:00
ncp libowfat: fix error with gcc-15 2025-04-19 14:36:07 -07:00
ndisc6 meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
netcat PATCH 2/8] netcat: inherit sourceforge-releases class 2025-11-09 06:52:51 -08:00
netcf netcf: remove EXTRA_AUTORECONF 2025-06-26 07:26:21 -07:00
netperf meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
netsniff-ng netsniff-ng: upgarde 0.6.8 -> 0.6.9 2025-11-08 23:04:38 -08:00
nis meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
ntimed meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
ntopng meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
ntp ntp: add UPSTREAM_CHECK_URI 2025-11-13 10:15:06 -08:00
ntpsec recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
nuttcp meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
open-isns meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
open-vm-tools open-vm-tools: Avoid GLib g_free macro redefinition error 2025-11-21 00:39:01 -08:00
openipmi openipmi: upgrade 2.0.36 -> 2.0.37 2025-11-18 08:23:44 -08:00
openvpn openvpn: upgrade 2.6.15 -> 2.6.16 2025-11-25 07:44:41 -08:00
pgpool2 pgpool2: upgrade 4.5.5 -> 4.6.3 2025-10-08 18:46:03 -07:00
phytool meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
pimd pimd: switch SRC_URI to https 2024-04-09 13:56:26 -07:00
rdma-core meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
ruli ruli: Fix build with clang 2025-07-18 21:02:45 -07:00
smcroute meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
sngrep meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
spice spice: update 0.15.2 -> 0.16.0 2025-10-29 21:02:20 -07:00
ssmping ssmping: Use debian mirror for SRC_URI 2025-04-06 08:47:56 -07:00
ssmtp ssmtp: fix build error with gcc-15 2025-04-19 14:36:02 -07:00
strongswan strongswan: upgrade 6.0.2 -> 6.0.3 2025-11-02 08:29:25 -08:00
stunnel atftp,tftp-hpa,vsftpd,dante,stunnel: Disable and remove tcp-wrapper support 2025-11-11 10:19:40 -08:00
tcpdump tcpdump: add CVE_PRODUCT 2024-11-21 21:42:35 -08:00
tcpreplay tcpreplay: add UPSTREAM_CHECK_REGEX 2025-11-09 06:52:52 -08:00
tinyproxy tinyproxy: upgrade 1.11.1 -> 1.11.2 2025-10-06 14:14:37 -07:00
tnftp tnftp: fix lib32-tnftp build failure with gcc-14 2024-06-14 10:20:37 -07:00
traceroute traceroute: upgrade 2.1.5 -> 2.1.6 2024-09-18 21:03:17 -07:00
tunctl tunctl: inherit sourceforge-releases class 2025-11-09 06:52:52 -08:00
udpcast udpcast: upgrade 20230924 -> 20250223 2025-03-11 17:17:24 -07:00
uftp uftp: upgrade 5.0.2 -> 5.0.3 2023-12-29 09:04:16 -08:00
unbound meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
vnstat
wavemon meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00
wireshark wireshark: Fix CVE-2025-9817 2025-11-04 16:52:46 -08:00
wpan-tools meta-openembedded/all: adapt to UNPACKDIR changes 2025-06-25 06:44:52 -07:00