OpenBSD Journal

LibreSSL 4.1.1 and 4.0.1 released

Contributed by grey on from the errata, a CVE, bug fixes and version bumps, oh my dept.

LibreSSL version 4.1.1 and 4.0.1 have been released.

The 4.1.1 release notes read:

We have released LibreSSL 4.1.1, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon.

It includes the following change from LibreSSL 4.1.0:

 * Bugfixes
   - OpenBSD 7.7 errata 010. An incorrect length check can result in a 4-byte
     overwrite and an 8-byte overread.
     From Stanislav Fort and Viktor Dukhovni via OpenSSL.
     CVE-2025-9230.

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.
Whereas these are the release notes for 4.0.1:

We have released LibreSSL 4.0.1, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon.

It includes the following change from LibreSSL 4.0.0:

 * Bugfixes
   - OpenBSD 7.6 errata 023. An incorrect length check can result in a 4-byte
     overwrite and an 8-byte overread.
     From Stanislav Fort and Viktor Dukhovni via OpenSSL.
     CVE-2025-9230.

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.

Latest Articles

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]