3 posts tagged#Security.
A security release. Upstream fixes a heap buffer overflow in HTTP/3 that needs an old OpenSSL to trigger, and closes two holes in the predicate location code that shipped two weeks ago.
A quiet release upstream, but the packaging around it changed a lot. Every third-party module is now dynamic, Brotli and Zstd moved to opt-in snippets, and the bundled OpenSSL jumps to 4.0.2.
Upstream fixes three security issues, including a heap buffer overflow in map with regex. Packages are live for all supported releases, upgrade now.