-
-
Notifications
You must be signed in to change notification settings - Fork 11.4k
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
genpkey support for PQ mechs: ML-KEM, ML-DSA, SLHDSA
issue: feature requestThe issue was opened to request a featureThe issue was opened to request a featureStatus: Open.#32392 In openssl/openssl;afl++ fuzzing takes and looong time for pkcs12-test
issue: bug reportThe issue was opened to report a bugThe issue was opened to report a bugStatus: Open.#32387 In openssl/openssl;Segfault when calling SSL_get0_group_name() before handshake
branch: 3.4Applies to openssl-3.4Applies to openssl-3.4branch: 3.5Applies to openssl-3.5Applies to openssl-3.5branch: 3.6Applies to openssl-3.6Applies to openssl-3.6branch: 4.0Applies to openssl-4.0Applies to openssl-4.0branch: masterApplies to master branchApplies to master branchtriaged: bugThe issue/pr is/fixes a bugThe issue/pr is/fixes a bugStatus: Open.#32379 In openssl/openssl;[robustness] OCSP_check_validity (ocsp_cl.c:323/:334/:350): X509_cmp_time error-0 read as PASS — non-5280 times silently skip freshness
branch: 3.0Applies to openssl-3.0 branchApplies to openssl-3.0 branchbranch: 3.4Applies to openssl-3.4Applies to openssl-3.4branch: 3.5Applies to openssl-3.5Applies to openssl-3.5branch: 3.6Applies to openssl-3.6Applies to openssl-3.6triaged: bugThe issue/pr is/fixes a bugThe issue/pr is/fixes a bugStatus: Open.#32377 In openssl/openssl;[robustness] OCSP_resp_find_status accepts contradictory duplicate-CertID response: good+revoked silently resolves to first entry
issue: bug reportThe issue was opened to report a bugThe issue was opened to report a bugStatus: Open.#32376 In openssl/openssl;[robustness] check_trust (x509_vfy.c:967): leaf REJECT entry skipped once the chain anchors → operator-blacklisted certificate accepted
issue: bug reportThe issue was opened to report a bugThe issue was opened to report a bugStatus: Open.#32375 In openssl/openssl;[robustness] check_extensions (x509_vfy.c:714): LONG_MAX pathLenConstraint + proxy cert → signed-long overflow → valid chain over-rejected
issue: bug reportThe issue was opened to report a bugThe issue was opened to report a bugStatus: Open.#32374 In openssl/openssl;nc_email_eai (v3_ncons.c:708-719): mailbox-form excluded rfc822Name never matches a SmtpUTF8Mailbox SAN → wrong accept
issue: bug reportThe issue was opened to report a bugThe issue was opened to report a bugStatus: Open.#32373 In openssl/openssl;[robustness] CMS PasswordRecipientInfo (cms_pwri.c:375): uncapped PBKDF2 iterationCount=2^31-1 pins one CPU ~5 min per recipient
issue: bug reportThe issue was opened to report a bugThe issue was opened to report a bugStatus: Open.#32372 In openssl/openssl;[robustness] crypto/pem/pvkfmt.c:897 check-after-use memcpy → ≤8-byte heap over-read on crafted PVK blob (keylen<8, legacy provider)
resolved: fixedThis issue has been fixedThis issue has been fixedtriaged: bugThe issue/pr is/fixes a bugThe issue/pr is/fixes a bugStatus: Open.#32371 In openssl/openssl;[robustness] apps/ec.c:245-249 check arm drops EVP_PKEY_check failure → openssl ec -check exits 0 "EC Key Invalid!" on invalid keys
issue: bug reportThe issue was opened to report a bugThe issue was opened to report a bugStatus: Open.#32370 In openssl/openssl;[robustness] apps/rsa.c:317 r==0 arm drops EVP_PKEY_check failure → openssl rsa -check exits 0 "RSA key not ok" on invalid private keys
issue: bug reportThe issue was opened to report a bugThe issue was opened to report a bugStatus: Open.#32369 In openssl/openssl;