untrusted comment: verify with openbsd-79-base.pub RWTSdNN9A3yvWAMJ3YJZvFf7QVitplYWIjKkBOCwZ/Je7V6IW9ERjIqTVi6jIrNYHQhrsJYasSNH1pQlrwltyKmPAdEgzJaqSAo= OpenBSD 7.9 errata 024, September 30, 2026: Fix a variety of bugs in libressl: - Remove RelativeDistinguishedName support for CRL distribution points - Ensure verify callbacks always returning 1 can see a hostname mismatch - Correct botched size check in dtls1_preprocess_fragment() - Limit size of buffered DTLS handshake messages - Avoid potential overread on interrupted retransmission in DTLS - Fix OCSP responder authorization bypass in libtls and ocspcheck(8) Apply by doing: signify -Vep /etc/signify/openbsd-79-base.pub -x 024_libressl.patch.sig \ -m - | (cd /usr/src && patch -p0) And then rebuild and install libcrypto, libssl, libtls, and ocspcheck: cd /usr/src/lib/libcrypto make obj make make install cd /usr/src/lib/libssl make obj make make install cd /usr/src/lib/libtls make obj make make install cd /usr/src/usr.sbin/ocspcheck make obj make make install Index: lib/libcrypto/man/x509v3.cnf.5 =================================================================== RCS file: /cvs/src/lib/libcrypto/man/x509v3.cnf.5,v diff -u -p -r1.8 x509v3.cnf.5 --- lib/libcrypto/man/x509v3.cnf.5 31 Mar 2022 17:27:17 -0000 1.8 +++ lib/libcrypto/man/x509v3.cnf.5 22 Sep 2026 03:59:59 -0000 @@ -364,11 +364,6 @@ If the name is the value field should contain the full name of the distribution point in the same format as subject alternative name. .Pp -If the name is -.Ic relativename , -then the value field should contain a section name whose contents -represent a DN fragment to be placed in this field. -.Pp The name .Ic CRLIssuer , if present, should contain a value for this field in subject Index: lib/libcrypto/x509/x509_crld.c =================================================================== RCS file: /cvs/src/lib/libcrypto/x509/x509_crld.c,v diff -u -p -r1.11 x509_crld.c --- lib/libcrypto/x509/x509_crld.c 7 Feb 2026 17:12:47 -0000 1.11 +++ lib/libcrypto/x509/x509_crld.c 22 Sep 2026 04:15:49 -0000 @@ -142,63 +142,30 @@ static int set_dist_point_name(DIST_POINT_NAME **pdp, X509V3_CTX *ctx, CONF_VALUE *cnf) { STACK_OF(GENERAL_NAME) *fnm = NULL; - STACK_OF(X509_NAME_ENTRY) *rnm = NULL; - if (!strcmp(cnf->name, "fullname")) { - fnm = gnames_from_sectname(ctx, cnf->value); - if (!fnm) - goto err; - } else if (!strcmp(cnf->name, "relativename")) { - int ret; - STACK_OF(CONF_VALUE) *dnsect; - X509_NAME *nm; - nm = X509_NAME_new(); - if (!nm) - return -1; - dnsect = X509V3_get0_section(ctx, cnf->value); - if (!dnsect) { - X509V3error(X509V3_R_SECTION_NOT_FOUND); - X509_NAME_free(nm); - return -1; - } - ret = X509V3_NAME_from_section(nm, dnsect, MBSTRING_ASC); - rnm = nm->entries; - nm->entries = NULL; - X509_NAME_free(nm); - if (!ret || sk_X509_NAME_ENTRY_num(rnm) <= 0) - goto err; - /* Since its a name fragment can't have more than one - * RDNSequence - */ - if (sk_X509_NAME_ENTRY_value(rnm, - sk_X509_NAME_ENTRY_num(rnm) - 1)->set) { - X509V3error(X509V3_R_INVALID_MULTIPLE_RDNS); - goto err; - } - } else + if (strcmp(cnf->name, "relativename") == 0) + return -1; + if (strcmp(cnf->name, "fullname") != 0) return 0; - if (*pdp) { + if (*pdp != NULL) { X509V3error(X509V3_R_DISTPOINT_ALREADY_SET); goto err; } + if ((*pdp = DIST_POINT_NAME_new()) == NULL) + goto err; - *pdp = DIST_POINT_NAME_new(); - if (!*pdp) + if ((fnm = gnames_from_sectname(ctx, cnf->value)) == NULL) goto err; - if (fnm) { - (*pdp)->type = 0; - (*pdp)->name.fullname = fnm; - } else { - (*pdp)->type = 1; - (*pdp)->name.relativename = rnm; - } + + (*pdp)->type = 0; + (*pdp)->name.fullname = fnm; return 1; -err: + err: sk_GENERAL_NAME_pop_free(fnm, GENERAL_NAME_free); - sk_X509_NAME_ENTRY_pop_free(rnm, X509_NAME_ENTRY_free); + return -1; } @@ -760,13 +727,6 @@ print_distpoint(BIO *out, DIST_POINT_NAM if (dpn->type == 0) { BIO_printf(out, "%*sFull Name:\n", indent, ""); print_gens(out, dpn->name.fullname, indent); - } else { - X509_NAME ntmp; - ntmp.entries = dpn->name.relativename; - BIO_printf(out, "%*sRelative Name:\n%*s", - indent, "", indent + 2, ""); - X509_NAME_print_ex(out, &ntmp, 0, XN_FLAG_ONELINE); - BIO_puts(out, "\n"); } return 1; } @@ -823,30 +783,8 @@ i2r_crldp(const X509V3_EXT_METHOD *metho int DIST_POINT_set_dpname(DIST_POINT_NAME *dpn, X509_NAME *iname) { - int i; - STACK_OF(X509_NAME_ENTRY) *frag; - X509_NAME_ENTRY *ne; - if (!dpn || (dpn->type != 1)) return 1; - frag = dpn->name.relativename; - dpn->dpname = X509_NAME_dup(iname); - if (!dpn->dpname) - return 0; - for (i = 0; i < sk_X509_NAME_ENTRY_num(frag); i++) { - ne = sk_X509_NAME_ENTRY_value(frag, i); - if (!X509_NAME_add_entry(dpn->dpname, ne, -1, i ? 0 : 1)) { - X509_NAME_free(dpn->dpname); - dpn->dpname = NULL; - return 0; - } - } - /* generate cached encoding of name */ - if (i2d_X509_NAME(dpn->dpname, NULL) < 0) { - X509_NAME_free(dpn->dpname); - dpn->dpname = NULL; - return 0; - } - return 1; + return 0; } LCRYPTO_ALIAS(DIST_POINT_set_dpname); Index: lib/libcrypto/x509/x509_purp.c =================================================================== RCS file: /cvs/src/lib/libcrypto/x509/x509_purp.c,v diff -u -p -r1.44 x509_purp.c --- lib/libcrypto/x509/x509_purp.c 10 May 2025 05:54:39 -0000 1.44 +++ lib/libcrypto/x509/x509_purp.c 22 Sep 2026 03:59:59 -0000 @@ -301,9 +301,6 @@ LCRYPTO_ALIAS(X509_supported_extension); static void setup_dp(X509 *x, DIST_POINT *dp) { - X509_NAME *iname = NULL; - int i; - if (dp->reasons) { if (dp->reasons->length > 0) dp->dp_reasons = dp->reasons->data[0]; @@ -312,19 +309,6 @@ setup_dp(X509 *x, DIST_POINT *dp) dp->dp_reasons &= CRLDP_ALL_REASONS; } else dp->dp_reasons = CRLDP_ALL_REASONS; - if (!dp->distpoint || (dp->distpoint->type != 1)) - return; - for (i = 0; i < sk_GENERAL_NAME_num(dp->CRLissuer); i++) { - GENERAL_NAME *gen = sk_GENERAL_NAME_value(dp->CRLissuer, i); - if (gen->type == GEN_DIRNAME) { - iname = gen->d.directoryName; - break; - } - } - if (!iname) - iname = X509_get_issuer_name(x); - - DIST_POINT_set_dpname(dp->distpoint, iname); } static void Index: lib/libcrypto/x509/x509_verify.c =================================================================== RCS file: /cvs/src/lib/libcrypto/x509/x509_verify.c,v diff -u -p -r1.76 x509_verify.c --- lib/libcrypto/x509/x509_verify.c 4 May 2026 13:55:20 -0000 1.76 +++ lib/libcrypto/x509/x509_verify.c 19 Sep 2026 18:33:24 -0000 @@ -760,8 +760,11 @@ x509_verify_cert_hostname(struct x509_ve if (ctx->xsc != NULL) { int ret; - if ((ret = x509_vfy_check_id(ctx->xsc)) == 0) + ret = x509_vfy_check_id(ctx->xsc); + if (ctx->xsc->error != X509_V_OK) { ctx->error = ctx->xsc->error; + ctx->error_depth = ctx->xsc->error_depth; + } return ret; } return 1; Index: lib/libssl/d1_both.c =================================================================== RCS file: /cvs/src/lib/libssl/d1_both.c,v diff -u -p -r1.85 d1_both.c --- lib/libssl/d1_both.c 9 Mar 2025 15:12:18 -0000 1.85 +++ lib/libssl/d1_both.c 19 Sep 2026 18:33:43 -0000 @@ -446,7 +446,7 @@ dtls1_preprocess_fragment(SSL *s, struct return SSL_AD_ILLEGAL_PARAMETER; } - if ((frag_off + frag_len) > (unsigned long)max) { + if (msg_len > (unsigned long)max) { SSLerror(s, SSL_R_EXCESSIVE_MESSAGE_SIZE); return SSL_AD_ILLEGAL_PARAMETER; } @@ -539,19 +539,21 @@ dtls1_retrieve_buffered_fragment(SSL *s, * but may be greater if the maximum certificate list size requires it. */ static unsigned long -dtls1_max_handshake_message_len(const SSL *s) +dtls1_max_handshake_message_len(const SSL *s, uint8_t msg_type) { unsigned long max_len; max_len = DTLS1_HM_HEADER_LENGTH + SSL3_RT_MAX_ENCRYPTED_LENGTH; - if (max_len < (unsigned long)s->max_cert_list) - return s->max_cert_list; + if (msg_type == SSL3_MT_CERTIFICATE && + max_len < (unsigned long)s->max_cert_list) + max_len = s->max_cert_list; return max_len; } static int -dtls1_reassemble_fragment(SSL *s, struct hm_header_st* msg_hdr, int *ok) +dtls1_reassemble_fragment(SSL *s, struct hm_header_st *msg_hdr, int *ok) { + piterator iter; hm_fragment *frag = NULL; pitem *item = NULL; int i = -1, is_complete; @@ -559,7 +561,7 @@ dtls1_reassemble_fragment(SSL *s, struct unsigned long frag_len = msg_hdr->frag_len; if ((msg_hdr->frag_off + frag_len) > msg_hdr->msg_len || - msg_hdr->msg_len > dtls1_max_handshake_message_len(s)) + msg_hdr->msg_len > dtls1_max_handshake_message_len(s, msg_hdr->type)) goto err; if (frag_len == 0) { @@ -574,6 +576,14 @@ dtls1_reassemble_fragment(SSL *s, struct item = pqueue_find(s->d1->buffered_messages, seq64be); if (item == NULL) { + /* Ensure that we only have one of each handshake message type. */ + iter = pqueue_iterator(s->d1->buffered_messages); + for (item = pqueue_next(&iter); item != NULL; item = pqueue_next(&iter)) { + frag = (hm_fragment *)item->data; + if (frag->msg_header.type == msg_hdr->type) + goto err; + } + frag = dtls1_hm_fragment_new(msg_hdr->msg_len, 1); if (frag == NULL) goto err; @@ -698,7 +708,7 @@ dtls1_process_out_of_seq_message(SSL *s, if (frag_len < msg_hdr->msg_len) return dtls1_reassemble_fragment(s, msg_hdr, ok); - if (frag_len > dtls1_max_handshake_message_len(s)) + if (frag_len > dtls1_max_handshake_message_len(s, msg_hdr->type)) goto err; frag = dtls1_hm_fragment_new(frag_len, 0); @@ -1030,6 +1040,7 @@ dtls1_retransmit_message(SSL *s, unsigne memcpy(s->init_buf->data, frag->fragment, frag->msg_header.msg_len + header_length); s->init_num = frag->msg_header.msg_len + header_length; + s->init_off = 0; dtls1_set_message_header_int(s, frag->msg_header.type, frag->msg_header.msg_len, frag->msg_header.seq, 0, Index: lib/libssl/d1_pkt.c =================================================================== RCS file: /cvs/src/lib/libssl/d1_pkt.c,v diff -u -p -r1.130 d1_pkt.c --- lib/libssl/d1_pkt.c 12 Mar 2025 14:03:55 -0000 1.130 +++ lib/libssl/d1_pkt.c 22 Sep 2026 04:35:12 -0000 @@ -210,7 +210,7 @@ dtls1_buffer_record(SSL *s, record_pqueu pitem *item = NULL; /* Limit the size of the queue to prevent DOS attacks */ - if (pqueue_size(queue->q) >= 100) + if (pqueue_size(queue->q) >= 16) return 0; if ((rdata = malloc(sizeof(*rdata))) == NULL) @@ -256,7 +256,7 @@ dtls1_buffer_rcontent(SSL *s, rcontent_p pitem *item = NULL; /* Limit the size of the queue to prevent DOS attacks */ - if (pqueue_size(queue->q) >= 100) + if (pqueue_size(queue->q) >= 16) return 0; if ((rdata = malloc(sizeof(*rdata))) == NULL) Index: lib/libtls/tls_ocsp.c =================================================================== RCS file: /cvs/src/lib/libtls/tls_ocsp.c,v diff -u -p -r1.29 tls_ocsp.c --- lib/libtls/tls_ocsp.c 16 Apr 2026 07:35:25 -0000 1.29 +++ lib/libtls/tls_ocsp.c 19 Sep 2026 18:33:24 -0000 @@ -217,22 +217,14 @@ tls_ocsp_verify_response(struct tls *ctx STACK_OF(X509) *combined = NULL; int response_status=0, cert_status=0, crl_reason=0; int ret = -1; - unsigned long flags; if ((br = OCSP_response_get1_basic(resp)) == NULL) { tls_set_errorx(ctx, TLS_ERROR_UNKNOWN, "cannot load ocsp reply"); goto err; } - /* - * Skip validation of 'extra_certs' as this should be done - * already as part of main handshake. - */ - flags = OCSP_TRUSTOTHER; - - /* now verify */ if (OCSP_basic_verify(br, ctx->ocsp->extra_certs, - SSL_CTX_get_cert_store(ctx->ssl_ctx), flags) != 1) { + SSL_CTX_get_cert_store(ctx->ssl_ctx), 0) != 1) { tls_set_errorx(ctx, TLS_ERROR_UNKNOWN, "ocsp verify failed"); goto err; } Index: usr.sbin/ocspcheck/ocspcheck.c =================================================================== RCS file: /cvs/src/usr.sbin/ocspcheck/ocspcheck.c,v diff -u -p -r1.34 ocspcheck.c --- usr.sbin/ocspcheck/ocspcheck.c 4 Dec 2024 07:58:51 -0000 1.34 +++ usr.sbin/ocspcheck/ocspcheck.c 19 Sep 2026 18:33:24 -0000 @@ -437,8 +437,7 @@ validate_response(char *buf, size_t size goto err; } - if (OCSP_basic_verify(bresp, request->fullchain, store, - OCSP_TRUSTOTHER) != 1) { + if (OCSP_basic_verify(bresp, request->fullchain, store, 0) != 1) { warnx("OCSP verify failed from %s", host); goto err; }