OpenBSD Journal

LibreSSL 4.2.2 and 4.3.3 released

Contributed by Peter N. M. Hansteen on from the TLS! TLS! Stable! dept.

In a move that hints strongly that the new OpenBSD release is about to drop soon, the LibreSSL project have announced the new stable releases.

The announcement reads,

List:       openbsd-announce
Subject:    LibreSSL 4.2.2 and 4.3.3 released
From:       Brent Cook <busterb () gmail ! com>
Date:       2026-10-06 0:38:40

We have released LibreSSL 4.3.3 and 4.2.2, which are available in the
LibreSSL directory of your local OpenBSD mirror.
LibreSSL 4.3.3 includes the following changes from 4.3.2:

 * Portable changes
   - Added support for building on macOS Golden Gate, 27.0
   - Fixed incorrect code generation by the MSVC ARM64 optimizer in
     constant-time bignum code.
   - Allow overriding TLS_DEFAULT_CA_FILE in CMake builds.
   - Windows socketpair() emulation now sets close-on-exec on the right
     handle.
 * Security and reliability fixes
   - Remove RelativeDistinguishedName support for CRL distribution points
   - Ensure verify callbacks always returning 1 can see a hostname
     mismatch
   - Correct botched size check in dtls1_preprocess_fragment()
   - Limit size of buffered DTLS handshake messages
   - Avoid potential overread on interrupted retransmission in DTLS
   - Fix OCSP responder authorization bypass in libtls and ocspcheck(8)

LibreSSL 4.2.2 includes the following changes from 4.2.1:

 * Portable changes
   - Added support for building on macOS Golden Gate, 27.0
   - Fixed incorrect code generation by the MSVC ARM64 optimizer in
     constant-time bignum code.
   - Windows socketpair() emulation now sets close-on-exec on the right
     handle.
 * Security and reliability fixes
   - Remove RelativeDistinguishedName support for CRL distribution points
   - Fix off-by-one in the X.509 verifier depth checking
   - Ensure verify callbacks always returning 1 can see a hostname
     mismatch
   - Correct botched size check in dtls1_preprocess_fragment()
   - Limit size of buffered DTLS handshake messages
   - Avoid potential overread on interrupted retransmission in DTLS
   - Fix OCSP responder authorization bypass in libtls and ocspcheck(8)

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.
So lots of goodness for your stable crypto life.

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]