[packages/mbedtls] - updated to 3.6.4 (fixes CVE-2025-49087 CVE-2025-52497 CVE-2025-48965 CVE-2025-47917 CVE-2025-52496

qboosh qboosh at pld-linux.org
Wed Jul 2 18:47:54 CEST 2025


commit a2b9d810f4aef99419278836bcc9bfe7eacbad30
Author: Jakub Bogusz <qboosh at pld-linux.org>
Date:   Wed Jul 2 18:49:22 2025 +0200

    - updated to 3.6.4 (fixes CVE-2025-49087 CVE-2025-52497 CVE-2025-48965 CVE-2025-47917 CVE-2025-52496 CVE-2025-49600 CVE-2025-49601)

 mbedtls.spec | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)
---
diff --git a/mbedtls.spec b/mbedtls.spec
index 2d5662d..f2d96e1 100644
--- a/mbedtls.spec
+++ b/mbedtls.spec
@@ -8,13 +8,13 @@
 Summary:	Light-weight cryptographic and SSL/TLS library
 Summary(pl.UTF-8):	Lekka biblioteka kryptograficzna oraz SSL/TLS
 Name:		mbedtls
-Version:	3.6.3.1
+Version:	3.6.4
 Release:	1
 License:	GPL v2+
 Group:		Libraries
 #Source0Download: https://github.com/Mbed-TLS/mbedtls/releases
-Source0:	https://github.com/Mbed-TLS/mbedtls/archive/v%{version}/%{name}-%{version}.tar.gz
-# Source0-md5:	ca72e14669a8fddc7d1bf154947ebd4c
+Source0:	https://github.com/Mbed-TLS/mbedtls/releases/download/%{name}-%{version}/%{name}-%{version}.tar.bz2
+# Source0-md5:	eb965a5bb8044bc43a49adb435fa72ee
 Patch0:		%{name}-config-dtls-srtp.patch
 URL:		https://www.trustedfirmware.org/projects/mbed-tls/
 BuildRequires:	cmake >= 3.5.1
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/mbedtls.git/commitdiff/a2b9d810f4aef99419278836bcc9bfe7eacbad30



More information about the pld-cvs-commit mailing list