Skip to content

Commit a0ec7f6

Browse files
julianbrostyhabteab
authored andcommitted
Icinga 2.12.12
1 parent 9b2c05d commit a0ec7f6

File tree

2 files changed

+16
-1
lines changed

2 files changed

+16
-1
lines changed

CHANGELOG.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,21 @@ documentation before upgrading to a new release.
77

88
Released closed milestones can be found on [GitHub](https://github.com/Icinga/icinga2/milestones?state=closed).
99

10+
## 2.12.12 (2025-05-27)
11+
12+
This security release fixes a critical issue in the certificate renewal logic in Icinga 2, which
13+
might incorrectly renew an invalid certificate. However, only nodes with access to the Icinga CA
14+
private key running with OpenSSL older than version 1.1.0 (released in 2016) are vulnerable. So this
15+
typically affects Icinga 2 masters running on operating systems like RHEL 7 and Amazon Linux 2.
16+
17+
* CVE-2025-48057: Prevent invalid certificates from being renewed with OpenSSL older than v1.1.0.
18+
* Fix use-after-free in VerifyCertificate(): Additionally, a use-after-free was found in the same
19+
function which is fixed as well, but in case it is triggered, typically only a wrong error code
20+
may be shown in a log message.
21+
* Windows: Update OpenSSL shipped on Windows to v3.0.16. #10455
22+
* Windows: Fix unknown ctest(1) `--log_level` argument. #10453
23+
* Don't require to build .msi as admin. #10454
24+
1025
## 2.12.11 (2024-11-12)
1126

1227
This security release fixes a TLS certificate validation bypass.

ICINGA2_VERSION

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
1-
Version: 2.12.11
1+
Version: 2.12.12
22
Revision: 1

0 commit comments

Comments
 (0)