Skip to content

add records for CVE's in release 5.9.4 - #31

Open
JacobBarthelmeh wants to merge 2 commits into
wolfSSL:masterfrom
JacobBarthelmeh:5.9.4
Open

JacobBarthelmeh wants to merge 2 commits into
wolfSSL:masterfrom
JacobBarthelmeh:5.9.4

Conversation

@JacobBarthelmeh

Copy link
Copy Markdown

No description provided.

@JacobBarthelmeh JacobBarthelmeh self-assigned this Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 16:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The missing 5.9.4 release catalogue prevents CI from generating and publishing the release bundle.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Adds 11 wolfSSL 5.9.4 CVE records and corresponding VEX metadata.

Changes:

  • Adds canonical CVE records, affected ranges, CVSS scores, and references.
  • Marks vulnerabilities fixed in 5.9.4 with remediation and build constraints.
File Description
advisories/​vex-overlay.json Adds VEX metadata for all 11 CVEs.
advisories/​records/​CVE-2026-94419.json Adds session-cache poisoning record.
advisories/​records/​CVE-2026-94418.json Adds signature-verification record.
advisories/​records/​CVE-2026-94417.json Adds OCSP/CRL bypass record.
advisories/​records/​CVE-2026-93304.json Adds early ChangeCipherSpec record.
advisories/​records/​CVE-2026-93302.json Adds trusted-peer validation record.
advisories/​records/​CVE-2026-89136.json Adds unsolicited RPK record.
advisories/​records/​CVE-2026-89135.json Adds CertManager poisoning record.
advisories/​records/​CVE-2026-89134.json Adds Subject CN constraint record.
advisories/​records/​CVE-2026-89133.json Adds NameConstraints record.
advisories/​records/​CVE-2026-89102.json Adds OCSP stapling v2 record.
advisories/​records/​CVE-2026-15442.json Adds shutdown use-after-free record.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread advisories/vex-overlay.json
@sameehj
sameehj requested review from MarkAtwood and sameehj October 1, 2026 17:30
@sameehj

sameehj commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Leave advisories/out/ and advisories/publish/ out of this pull request. Those files are built from the CVE records, the overlay, and the release directory. CI rebuilds them on every pull request and checks the schema, the hashes, and the publish layout. A copy in git can disagree with those sources. The signed files are made at deploy with the gpg key.

@JacobBarthelmeh

Copy link
Copy Markdown
Author

Leave advisories/out/ and advisories/publish/ out of this pull request. Those files are built from the CVE records, the overlay, and the release directory. CI rebuilds them on every pull request and checks the schema, the hashes, and the publish layout. A copy in git can disagree with those sources. The signed files are made at deploy with the gpg key.

Sounds good, I think they were not checked in, and currently are left out? Let me know though if I missed excluding them and should make some changes to the PR.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The release catalogue, records, changelog membership, and VEX fixed-version metadata are internally consistent.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants