mbedtls: Update to 2.28.9
authorHauke Mehrtens <hauke@hauke-m.de>
Wed, 11 Sep 2024 21:03:50 +0000 (23:03 +0200)
committerHauke Mehrtens <hauke@hauke-m.de>
Sat, 14 Sep 2024 15:02:22 +0000 (17:02 +0200)
commita0ebff651d41ce7c892b24785b0edc04fba1341c
treed2cac2f2c078f2bbe2188b6f3a7fcf58d07eaacf
parent8e5e62416f9c4fcd3b3ad1934b8d87e1d99cbc7e
mbedtls: Update to 2.28.9

This contains a fix for:
CVE-2024-45157:
Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does
not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when
MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.

Link: https://github.com/openwrt/openwrt/pull/16367
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
package/libs/mbedtls/Makefile
package/libs/mbedtls/patches/100-x509-crt-verify-SAN-iPAddress.patch