<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[wolfSSL - Embedded SSL Library — wolfEngine 1.4.1 Now Available]]></title>
		<link>https://www.wolfssl.com/forums/topic2571-wolfengine-141-now-available.html</link>
		<atom:link href="https://www.wolfssl.com/forums/feed-rss-topic2571.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in wolfEngine 1.4.1 Now Available.]]></description>
		<lastBuildDate>Mon, 31 Aug 2026 18:33:56 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[wolfEngine 1.4.1 Now Available]]></title>
			<link>https://www.wolfssl.com/forums/post8927.html#p8927</link>
			<description><![CDATA[<p><a href="https://github.com/wolfSSL/wolfEngine">wolfEngine version 1.4.1</a> is officially here. Built as an OpenSSL engine backed by the wolfCrypt FIPS 140-3 cryptographic module, wolfEngine brings FIPS-validated cryptography to legacy OpenSSL 1.0.2 and 1.1.1 applications without requiring application code changes. This update delivers critical security fixes for two TLS AEAD nonce-reuse vulnerabilities, along with FIPS enhancements and a comprehensive hardening pass.</p><p><span class="bbu"><strong>Interoperability and FIPS Enhancements</strong></span><br /></p><ul><li><p>AES-CTR no longer reinitializes after keying, preserving proper state across operations.</p></li></ul><ul><li><p>ECC and MAC modules now interoperate smoothly with OpenSSL 1.0.2r.</p></li></ul><ul><li><p>Replaced AES_BLOCK_SIZE with WC_AES_BLOCK_SIZE across all source files.</p></li></ul><ul><li><p>Integrated mandatory initialization logic required by the current wolfSSL-FIPS module.</p></li></ul><ul><li><p>Added simplified build scripts and resolved path issues for non-standard install locations.</p></li></ul><p><span class="bbu"><strong>Security Hardening</strong></span><br />The 1.4.1 release includes a thorough code cleanup to harden the engine against edge-case failures. Control handlers for <strong>AES-ECB</strong>, <strong>AES-CBC</strong>, and <strong>DES3-CBC</strong> now have corrected NULL checks, while key object cleanup logic for <strong>RSA</strong>, <strong>DH</strong>, and <strong>ASN.1</strong> has been hardened against assignment errors. <strong>ASN.1</strong> parsing for <strong>ECDSA</strong> signatures and <strong>HMAC</strong> enforces strict length bounds, and TLS record lengths for <strong>AES-CBC-HMAC</strong> are validated against underflow. Additionally, private-key BIGNUMs, buffered <strong>GCM</strong> plaintext, and derived keys are zeroized immediately after use. Pre-set <strong>DH</strong> private keys longer than the prime are also rejected during key generation, closing a heap write vulnerability.</p><p><span class="bbu"><strong>Security Fixes</strong></span></p><p><strong>CVE-2026-81020, AES-GCM Nonce Reuse on TLS 1.2 and DTLS 1.2</strong><br />Severity, High. Affects wolfEngine 0.9.0 through 1.4.0.<br />The 8-byte explicit nonce was generated once and failed to increment per record. Because every AES-GCM record within a connection reused the same key and nonce pair, both confidentiality and integrity were compromised. TLS 1.3 and non-TLS uses are unaffected. This impacts wolfEngine versions 0.9.0 through 1.4.0 in both FIPS and non-FIPS builds.</p><p><strong>CVE-2026-81341, AES-CCM Nonce Reuse on TLS 1.2 and DTLS 1.2</strong><br />Severity, Medium. Affects wolfEngine 0.9.0 through 1.4.0.<br />The explicit nonce was pulled from the record input buffer instead of the TLS sequence number, causing static nonce reuse across records. Exposure is reduced because AES-CCM cipher suites require explicit opt-in. TLS 1.3 and non-TLS modes remain unaffected. This impacts versions 0.9.0 through 1.4.0.</p><p><span class="bbu"><strong>Download and Upgrading</strong></span><br />Anyone using TLS 1.2 or DTLS 1.2 with <strong>AES-GCM</strong> or <strong>AES-CCM</strong> through wolfEngine should update to 1.4.1 immediately.</p><p>Grab the latest release on GitHub at <a href="https://github.com/wolfSSL/wolfEngine">https://github.com/wolfSSL/wolfEngine</a> and review the included ChangeLog for full release notes.</p><p>For general questions, FIPS 140-3 details, or commercial licensing, contact <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a>. For technical support, reach out to <a href="mailto:support@wolfssl.com">support@wolfssl.com</a>.</p><p><strong><a href="https://www.wolfssl.com/download/">Download</a> wolfSSL Now</strong></p>]]></description>
			<author><![CDATA[null@example.com (shizuka)]]></author>
			<pubDate>Mon, 31 Aug 2026 18:33:56 +0000</pubDate>
			<guid>https://www.wolfssl.com/forums/post8927.html#p8927</guid>
		</item>
	</channel>
</rss>
