Skip to content

build(deps): bump openssl from 3.5.5.bcr.3 to 4.0.1.bcr.0 in /src - #664

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bazel/src/master/openssl-4.0.1.bcr.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bazel/src/master/openssl-4.0.1.bcr.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 11, 2026

Copy link
Copy Markdown
Contributor

Bumps openssl from 3.5.5.bcr.3 to 4.0.1.bcr.0.

Release notes

Sourced from openssl's releases.

OpenSSL 3.5.7 is a security patch release. The most severe CVE fixed in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed heap use-after-free in PKCS7_verify(). ([CVE-2026-45447])

  • Fixed CMS AuthEnvelopedData processing may accept forged messages. ([CVE-2026-34182])

  • Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. ([CVE-2026-34183])

  • Fixed NULL pointer dereference in QUIC server initial packet handling. ([CVE-2026-42764])

  • Fixed AES-OCB IV ignored on EVP_Cipher() path. ([CVE-2026-45445])

  • Fixed possible heap buffer overflow in ASN.1 multibyte string conversion. ([CVE-2026-7383])

  • Fixed out-of-bounds read in CMS password-based decryption. ([CVE-2026-9076])

  • Fixed heap buffer over-read in ASN.1 content parsing. ([CVE-2026-34180])

  • Fixed PKCS#12 files with PBMAC1 are accepted with short HMAC keys. ([CVE-2026-34181])

  • Fixed possible NULL dereference in password-dased CMS decryption. ([CVE-2026-42766])

  • Fixed NULL pointer dereference in CRMF EncryptedValue decryption. ([CVE-2026-42767])

  • Fixed multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt(). ([CVE-2026-42768])

  • Fixed trust anchor substitution via cert/issuer typo in CMP rootCaKeyUpdate. ([CVE-2026-42769])

  • Fixed FFC-DH peer validation uses attacker-supplied q. ([CVE-2026-42770])

  • Fixed incorrect tag processing for empty messages in AES-GCM-SIV

... (truncated)

Changelog

Sourced from openssl's changelog.

NEWS

This file gives a brief overview of the major changes between each OpenSSL release. For more details please read the CHANGES file.

OpenSSL Releases

OpenSSL 4.1

Major changes between OpenSSL 4.0 and OpenSSL 4.1 [under development]

  • API calls CRYPTO_atomic_load_ptr, CRYPTO_atomic_store_ptr, and CRYPTO_atomic_cmp_exch_ptr have been added.

  • Initial support for the Elbrus2000 (e2k) architecture

  • Fixed verification of DSA certificates signed with SHA-384 or SHA-512.

OpenSSL 4.0

Major changes between OpenSSL 4.0.0 and OpenSSL 4.0.1 [9 Jun 2026]

OpenSSL 4.0.1 is a security patch release. The most severe CVE fixed in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed heap use-after-free in PKCS7_verify(). ([CVE-2026-45447])

  • Fixed CMS AuthEnvelopedData processing may accept forged messages.

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [openssl](https://github.com/openssl/openssl) from 3.5.5.bcr.3 to 4.0.1.bcr.0.
- [Release notes](https://github.com/openssl/openssl/releases)
- [Changelog](https://github.com/openssl/openssl/blob/master/NEWS.md)
- [Commits](https://github.com/openssl/openssl/commits)

---
updated-dependencies:
- dependency-name: openssl
  dependency-version: 4.0.1.bcr.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added bazel Pull requests that update bazel code dependencies Pull requests that update a dependency file labels Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bazel Pull requests that update bazel code dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants