Skip to content

Conversation

@tormath1
Copy link
Contributor

@tormath1 tormath1 commented Jan 28, 2026

In this PR, we sync with ::gentoo the 3.5.5 release of OpenSSL for alpha, beta and main branches. Please note that the current releases: alpha-4593.0.0, beta-4547.1.0 and stable-4459.2.3 are already safe against those CVEs (read more about this here: https://www.flatcar.org/blog/2022/11/about-the-handling-of-embargoed-security-issues/)

Testing done

emerge -pv openssl

Commit-ref: gentoo/gentoo@492effc

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did you mean to commit this change?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oops, thanks the heads-up.

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
@tormath1 tormath1 merged commit ce703f9 into main Jan 29, 2026
4 of 5 checks passed
@github-project-automation github-project-automation bot moved this from ✅ Testing / in Review to Implemented in Flatcar tactical, release planning, and roadmap Jan 29, 2026
@tormath1 tormath1 deleted the tormath1/openssl-3.5.5 branch January 29, 2026 08:21
@tormath1
Copy link
Contributor Author

Cherry-picked to:

  • flatcar-4593
  • flatcar-4547

Retagged:

  • alpha-4593.0.0
  • beta-4547.1.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Development

Successfully merging this pull request may close these issues.

3 participants