LibreSSL 4.3.3 Released with OCSP Authorization Bypass Fix

LibreSSL 4.3.3 addresses an OCSP responder authorization bypass, several DTLS issues, and improves portability across macOS and Windows.

LibreSSL 4.3.3 has been released as a maintenance update to the OpenBSD-developed TLS and cryptography library, bringing several security and reliability fixes alongside portability improvements for macOS and Windows.

The most notable fix in LibreSSL 4.3.3 addresses an Online Certificate Status Protocol responder authorization bypass affecting both libtls and the ocspcheck utility.

OCSP is used to determine whether a TLS certificate has been revoked. LibreSSL’s fix tightens validation around which responders are authorized to provide that information.

DTLS, which provides TLS-style encryption for datagram-based protocols such as UDP, also receives several corrections. The developers fixed an incorrect size check in dtls1_preprocess_fragment(). They introduced a limit on buffered DTLS handshake data and addressed a potential overread that could occur when retransmission was interrupted.

Certificate verification receives attention as well. LibreSSL 4.3.3 ensures that verification callbacks configured to always return success can still detect a hostname mismatch. In addition, support for RelativeDistinguishedName in CRL distribution points has been removed.

On the portability side, the release adds support for building LibreSSL on macOS Golden Gate 27.0.

Windows users also get a couple of fixes. The developers worked around incorrect code generation produced by the MSVC ARM64 optimizer in constant-time big-number code, while LibreSSL’s Windows socketpair() emulation now correctly sets close-on-exec on the appropriate handle.

Lastly, projects building LibreSSL through CMake can now override TLS_DEFAULT_CA_FILE, providing more flexibility over the default location used for trusted certificate authorities.

For additional detail, see the release notes.

LibreSSL is a fork of OpenSSL created by the OpenBSD project in 2014, focusing on simplifying the codebase, removing legacy components, and improving security and maintainability. Besides being used by OpenBSD, a portable version is available for Linux, macOS, Windows, and other Unix-like systems.

Bobby Borisov

Bobby Borisov

Bobby, an editor-in-chief at Linuxiac, is a Linux professional with over 20 years of experience. With a strong focus on Linux and open-source software, he has worked as a Senior Linux System Administrator, Software Developer, and DevOps Engineer for small and large multinational companies.

Leave a Reply

Your email address will not be published. Required fields are marked *