This release is based on LibreSSL 3.5.1:
https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.5.1-relnotes.txt
No changes were made to libtls code.
A release tarball for this version can be downloaded from:
https://causal.agency/libretls/libretls-3.5.1.tar.gz
----- Original message -----
From: Brent Cook <busterb@gmail.com>
To: announce@openbsd.org
Cc: libressl@openbsd.org
Subject: LibreSSL 3.3.6, 3.4.3, 3.5.1 Released
Date: Tuesday, March 15, 2022 13:25
We have released LibreSSL 3.3.6, 3.4.3, and 3.5.1, which will be
arriving in the LibreSSL directory of your local OpenBSD mirror soon.
They include the following security fix:
* A malicious certificate can cause an infinite loop.
Reported by and fix from Tavis Ormandy and David Benjamin, Google.
The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.