4 hours ago
openssl

OpenSSL 3.4.8

OpenSSL 3.4.8 is a security patch release. The most severe CVE fixed in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782)

  • Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189)

  • Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772)

  • Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872)

  • Fixed QUIC STREAM fragment metadata DoS. (CVE-2026-54873)

  • Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875)

  • Fixed out-of-bounds access after SSL_set_SSL_CTX() during a handshake. (CVE-2026-72897)

  • Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804)

  • Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805)

  • Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806)

  • Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696)

  • Fixed an unbounded RETIRE_CONNECTION_ID backlog in QUIC stack implementation. (CVE-2026-84784)

4 hours ago
openssl

OpenSSL 3.5.9

OpenSSL 3.5.9 is a security patch release. The most severe CVE fixed in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782)

  • Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189)

  • Fixed QUIC unvalidated amplification credit may be over-accounted. (CVE-2026-35191)

  • Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772)

  • Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872)

  • Fixed QUIC STREAM fragment metadata DoS. (CVE-2026-54873)

  • Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875)

  • Fixed out-of-bounds access after SSL_set_SSL_CTX() during a handshake. (CVE-2026-72897)

  • Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804)

  • Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805)

  • Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806)

  • Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696)

  • Fixed an unbounded RETIRE_CONNECTION_ID backlog in QUIC stack implementation. (CVE-2026-84784)

  • Fixed a bug where EVP_DecryptFinal() incorrectly reported a stale success on AES-SIV authentication failure.

4 hours ago
openssl

OpenSSL 3.6.5

OpenSSL 3.6.5 is a security patch release. The most severe CVE fixed in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782)

  • Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189)

  • Fixed QUIC unvalidated amplification credit may be over-accounted. (CVE-2026-35191)

  • Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772)

  • Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872)

  • Fixed QUIC STREAM fragment metadata DoS. (CVE-2026-54873)

  • Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875)

  • Fixed out-of-bounds access after SSL_set_SSL_CTX() during a handshake. (CVE-2026-72897)

  • Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804)

  • Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805)

  • Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806)

  • Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696)

  • Fixed an unbounded RETIRE_CONNECTION_ID backlog in QUIC stack implementation. (CVE-2026-84784)

  • Fixed a bug where EVP_DecryptFinal() incorrectly reported a stale success on AES-SIV authentication failure.

4 hours ago
timescaledb

2.30.2 (2026-09-29)

This release contains bug fixes since the 2.30.1 release. We recommend that you upgrade at the next available opportunity.

Bugfixes

  • #10665 Fix crash when merging chunks with different column layouts
  • #10668 Fix DROP SCHEMA CASCADE leaving orphaned compressed chunks
  • #10682 Fix vectorized text comparison ignoring a non-deterministic collation given in the query
  • #10609 Fix race while updating granular refresh setting for hypertable
  • #10613 Rename the granular refresh options to timescaledb.cagg_granular_refresh_*
  • #10636 Free the tenant tracker's shared memory when its hypertable is dropped
  • #10585 Potential crash in CREATE TABLE AS query selecting from a compressed hypertable
4 hours ago
openssl

OpenSSL 4.0.3

OpenSSL 4.0.3 is a security patch release. The most severe CVE fixed in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782)

  • Fixed a use-after-free in X.509 extension cache under concurrent use. (CVE-2026-84783)

  • Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189)

  • Fixed QUIC unvalidated amplification credit may be over-accounted. (CVE-2026-35191)

  • Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772)

  • Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872)

  • Fixed QUIC STREAM fragment metadata DoS. (CVE-2026-54873)

  • Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875)

  • Fixed out-of-bounds access after SSL_set_SSL_CTX() during a handshake. (CVE-2026-72897)

  • Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804)

  • Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805)

  • Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806)

  • Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696)

  • Fixed an unbounded RETIRE_CONNECTION_ID backlog in QUIC stack implementation. (CVE-2026-84784)

  • Fixed a bug where EVP_DecryptFinal() incorrectly reported a stale success on AES-SIV authentication failure.

  • Fixed a regression in base64 encoding BIO filter introduced in OpenSSL 4.0, where incomplete writes down the BIO chain may result in the loss of encoded base64 data.

6 hours ago
MeiliSearch

v1.54.2

Meilisearch v1.54.2 contains an important fix for users of the dynamicSearchRule experimental feature.

🦋 Fixes