<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[wolfSSL - Embedded SSL Library — wolfSSL 5.8.4 Now Available]]></title>
		<link>https://www.wolfssl.com/forums/topic2424-wolfssl-584-now-available.html</link>
		<atom:link href="https://www.wolfssl.com/forums/feed-rss-topic2424.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in wolfSSL 5.8.4 Now Available.]]></description>
		<lastBuildDate>Fri, 21 Nov 2025 22:26:16 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[wolfSSL 5.8.4 Now Available]]></title>
			<link>https://www.wolfssl.com/forums/post8618.html#p8618</link>
			<description><![CDATA[<p>wolfSSL 5.8.4 introduces several updates, including the addition of a GPLv3 exceptions list. This allows specific GPLv3-licensed codebases linking against wolfSSL to continue using wolfSSL under GPLv2.</p><br /><p><strong>Current GPLv3 Exception:</strong><br /></p><ul><li><p>MariaDB Server</p></li></ul><ul><li><p>MariaDB Client Libraries</p></li></ul><ul><li><p>OpenVPN-NL</p></li></ul><ul><li><p>Fetchmail</p></li></ul><ul><li><p>OpenVPN</p></li></ul><br /><p><strong>Security Fixes</strong></p><p>This release includes multiple fixes across TLS 1.2, TLS 1.3, X25519, XChaCha20-Poly1305, and PSK processing. Highlights include:<br /></p><ul><li><p>A timing-side-channel issue in X25519 specifically affecting Xtensa-based ESP32 devices. Low-memory X25519 implementations are now the default for Xtensa.</p></li></ul><ul><li><p>A medium-severity TLS 1.3 server-side DoS risk from repeated KeyShareEntry values in malicious ClientHello messages.</p></li></ul><ul><li><p>Several TLS 1.3 downgrade-related issues (PFS downgrades, signature algorithm downgrades, and duplicate extension parsing).</p></li></ul><ul><li><p>A memory leak risk in TLS 1.2 certificate digest handling.</p></li></ul><ul><li><p>XChaCha20-Poly1305 decryption bounds-check fix and constant-time improvements in PSK binder verification.</p></li></ul><p>Special thanks to Adrian Cinal, Jaehun Lee, and Kyungmin Bae (POSTECH), Luigino Camastra (Aisle Research), and all researchers who contributed.</p><br /><p><strong>New Features</strong></p><p>This release includes focused improvements and additions:<br /></p><ul><li><p><strong>ML-KEM / ML-DSA</strong>: new APIs, PKCS8 seed/import support, and improved key management.</p></li></ul><ul><li><p><strong>FreeBSD kernel module</strong>: initial support for wolfCrypt in the FreeBSD kernel.</p></li></ul><ul><li><p><strong>PKCS7/CMS</strong>: expanded decoding capabilities, additional callbacks, and more flexible builds.</p></li></ul><ul><li><p><strong>Rust wrapper enhancements</strong>: broader algorithm coverage, optional heap/dev_id support, and conditional compilation based on C build options.</p></li></ul><ul><li><p><strong>Hardware platform update</strong>s: STM32 and PSoC6 improvements, including STM32U5 SAES support.</p></li></ul><ul><li><p>New –enable-curl=tiny option for smaller cURL-linked builds.</p></li></ul><br /><p><strong>Improvements &amp; Optimizations</strong></p><p>Key improvements include:<br /></p><ul><li><p>Broader and more consistent testing across TLS 1.3/1.2, libssh2, Arduino, ESP-IDF, and nightly workflows.</p></li></ul><ul><li><p>Documentation updates, expanded crypto-callback support, and improved AES/HW offload functionality.</p></li></ul><ul><li><p>ESP32, Renesas FSP/RA, and SGX build enhancements.</p></li></ul><ul><li><p>Build-system refinements across Autotools, CMake, Apple platforms, and Debian packaging.</p></li></ul><ul><li><p>RISC-V and PPC32 assembly introspection helpers and benchmarking updates.</p></li></ul><br /><p><strong>Bug Fixes</strong></p><p>Notable fixes:<br /></p><ul><li><p>C# wrapper correction for Ed25519 raw public-key import.</p></li></ul><ul><li><p>Sniffer stability fixes and X.509 path-length and certificate-chain improvements.</p></li></ul><ul><li><p>DTLS ordering, cookie handling, and replay protection updates.</p></li></ul><ul><li><p>Kernel-mode, FIPS, and PIE-related build fixes.</p></li></ul><ul><li><p>ML-KEM/ML-DSA correctness and safety fixes.</p></li></ul><ul><li><p>Various static-analysis, warning cleanup, memory-management, and undefined-behavior fixes.</p></li></ul><br /><p>For a more detailed list of changes, check out the <a href="https://github.com/wolfSSL/wolfssl/blob/master/ChangeLog.md">ChangeLog.md</a> bundled with wolfSSL. To download the latest release, go to the <a href="https://www.wolfssl.com/download/">download page</a>. For any questions, reach out to us at <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a> or call us at +1 425 245 8247.</p><p><strong><a href="https://www.wolfssl.com/download/">Download</a> wolfSSL Now</strong></p>]]></description>
			<author><![CDATA[null@example.com (shizuka)]]></author>
			<pubDate>Fri, 21 Nov 2025 22:26:16 +0000</pubDate>
			<guid>https://www.wolfssl.com/forums/post8618.html#p8618</guid>
		</item>
	</channel>
</rss>
