{"id":169694,"date":"2026-04-21T18:24:39","date_gmt":"2026-04-21T16:24:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/libressl-4-3-0"},"modified":"2026-04-21T18:24:39","modified_gmt":"2026-04-21T16:24:39","slug":"libressl-4-3-0","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/libressl-4-3-0","title":{"rendered":"LibreSSL 4.3.0","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The LibreSSL project has announced the release of version 4.3.0, which is now available on OpenBSD mirrors.<\/p>\n<p>This is a development release for the 4.3.x branch, so the developers encourage the community to actively test it. No further API or ABI changes are planned for the 4.3 branch.<\/p>\n<p>A key innovation in this version is support for the post-quantum key exchange method MLKEM768_X25519 in TLS, in accordance with IETF draft-ietf-tls-ecdhe-mlkem. A \"off-by-one\" error in the X.509 certificate depth check has been fixed, which could have led to overwriting 4 bytes in memory when handling malicious data or when client certificate checks were enabled. The maximum depth is now limited to 32. The issue was discovered by Calif.io in collaboration with Claude and Anthropic Research. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-prohoster\/\" title=\"proxy server\" data-wpil-keyword-link=\"linked\">proxy server<\/a> Internal improvements:<\/p>\n<p>Obsolete code fragments remaining from SSLv2 and SSLv3\/TLS 1.0 support have been removed.<\/p>\n<ul>\n<li>ec_point_cmp() has been rewritten.<\/li>\n<li>A fast path for well-known DH primes, including those from RFC 7919, has been added to DH_check().<\/li>\n<li>Compatibility changes:<\/li>\n<\/ul>\n<p>Numerous unused macros BN_* with uninformative names (BN_LONG, BN_BITS4, BN_MASK2, etc.) have been removed.<\/p>\n<ul>\n<li>The openssl(1) cms command no longer accepts unsupported keys -compress and -uncompress.<\/li>\n<li>A PKCS7_NO_DUAL_CONTENT flag has been added for compatible behavior with some language bindings.<\/li>\n<li>Memory leaks in CMS_EncryptedData_encrypt() and nref_nos() have been fixed.<\/li>\n<\/ul>\n<p>Bug fixes:<\/p>\n<ul>\n<li>Bit string encoding with trailing zeroes has been corrected.<\/li>\n<li>A crash while parsing PKCS#12 and timestamp responses has been resolved.<\/li>\n<li>Numerous bugs in libtls (length checks, consistency of error messages) have been fixed.<\/li>\n<li>Support for the RSASSA-PSS algorithm with OID has been added to libssl.<\/li>\n<\/ul>\n<p>Miscellaneous:<\/p>\n<ul>\n<li>Functions X509_VERIFY_PARAM_set_hostflags() and SSL_SESSION_dup() have been added to the public API.<\/li>\n<li>BIGNUM now uses standard C99 types (uint64_t\/uint32_t), resolving issues on 64-bit Windows.<\/li>\n<li>Firefox release 150 has resolved 359 vulnerabilities.<\/li>\n<\/ul>\n<p>Source: <a rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/bsd\/18270274\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u043e\u0435\u043a\u0442 LibreSSL \u043e\u0431\u044a\u044f\u0432\u0438\u043b \u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 4.3.0, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0443\u0436\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430 \u043d\u0430 \u0437\u0435\u0440\u043a\u0430\u043b\u0430\u0445 OpenBSD. \u042d\u0442\u043e development-\u0432\u044b\u043f\u0443\u0441\u043a \u0434\u043b\u044f \u0432\u0435\u0442\u043a\u0438 4.3.x, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u0438\u0437\u044b\u0432\u0430\u044e\u0442 \u0441\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u043a \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u043c\u0443 \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044e. \u0414\u0430\u043b\u044c\u043d\u0435\u0439\u0448\u0438\u0445 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 API \u0438 ABI \u0432 \u0432\u0435\u0442\u043a\u0435 4.3 \u043d\u0435 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f. \u041a\u043b\u044e\u0447\u0435\u0432\u044b\u043c \u043d\u043e\u0432\u043e\u0432\u0432\u0435\u0434\u0435\u043d\u0438\u0435\u043c \u044d\u0442\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0441\u0442\u0430\u043b\u0430 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u043f\u043e\u0441\u0442\u043a\u0432\u0430\u043d\u0442\u043e\u0432\u043e\u0433\u043e \u043c\u0435\u0442\u043e\u0434\u0430 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0430\u043c\u0438 MLKEM768_X25519 \u0432 TLS \u0432 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0438 \u0441 \u0447\u0435\u0440\u043d\u043e\u0432\u0438\u043a\u043e\u043c IETF draft-ietf-tls-ecdhe-mlkem. \u0423\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-169694","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u043e\u0435\u043a\u0442 LibreSSL \u043e\u0431\u044a\u044f\u0432\u0438\u043b \u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 4.3.0, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0443\u0436\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430 \u043d\u0430 \u0437\u0435\u0440\u043a\u0430\u043b\u0430\u0445 OpenBSD. \u042d\u0442\u043e development-\u0432\u044b\u043f\u0443\u0441\u043a \u0434\u043b\u044f \u0432\u0435\u0442\u043a\u0438 4.3.x, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u0438\u0437\u044b\u0432\u0430\u044e\u0442 \u0441\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u043a \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u043c\u0443 \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/libressl-4-3-0\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47LibreSSL 4.3.0 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u043e\u0435\u043a\u0442 LibreSSL \u043e\u0431\u044a\u044f\u0432\u0438\u043b \u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 4.3.0, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0443\u0436\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430 \u043d\u0430 \u0437\u0435\u0440\u043a\u0430\u043b\u0430\u0445 OpenBSD. \u042d\u0442\u043e development-\u0432\u044b\u043f\u0443\u0441\u043a \u0434\u043b\u044f \u0432\u0435\u0442\u043a\u0438 4.3.x, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u0438\u0437\u044b\u0432\u0430\u044e\u0442 \u0441\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u043a \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u043c\u0443 \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/libressl-4-3-0\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-04-21T16:24:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-04-21T16:24:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47LibreSSL 4.3.0 | ProHoster","description":"\ud83e\udd47LibreSSL 4.3.0 | ProHoster","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/libressl-4-3-0","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47LibreSSL 4.3.0 | ProHoster","og:description":"\u041f\u0440\u043e\u0435\u043a\u0442 LibreSSL \u043e\u0431\u044a\u044f\u0432\u0438\u043b \u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 4.3.0, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0443\u0436\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430 \u043d\u0430 \u0437\u0435\u0440\u043a\u0430\u043b\u0430\u0445 OpenBSD. \u042d\u0442\u043e development-\u0432\u044b\u043f\u0443\u0441\u043a \u0434\u043b\u044f \u0432\u0435\u0442\u043a\u0438 4.3.x, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u0438\u0437\u044b\u0432\u0430\u044e\u0442 \u0441\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u043a \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u043c\u0443 \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044e.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/libressl-4-3-0","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-04-21T16:24:39+00:00","article:modified_time":"2026-04-21T16:24:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/169694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=169694"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/169694\/revisions"}],"predecessor-version":[{"id":170734,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/169694\/revisions\/170734"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=169694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=169694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=169694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}