Welcome! Log In Create A New Profile

Advanced

Re: [ANN] OpenResty 1.25.3.2 released

Jiahao Wang via nginx
July 22, 2024 04:46AM
We have fully understood the cause of the problem. The reason for disabling
rather than reverting the entire commit is because we want to continue to
use SSE to speed things up in the future.

On Mon, Jul 22, 2024 at 4:10 PM Mathew Heard <me@mheard.com> wrote:

> Now that there is a patch out could you please share more information
> on those "specific circumstances"?
>
> It looks to me that luajit2 does not support SSE4.2 whereas agentzh's
> fork does. And this is what has been disabled in this release. Is this
> an interim release while the cause is investigated or is it fully
> understood?
>
> On Mon, 22 Jul 2024 at 17:46, Jiahao Wang via nginx <nginx@nginx.org>
> wrote:
> >
> > Hi folks,
> >
> > I am happy to announce the new formal release, 1.25.3.2, of our
> OpenResty web platform based on NGINX and LuaJIT.
> >
> > OpenResty 1.25.3.2 is a security update addressing a performance issue
> in our OpenResty branch of LuaJIT related to hash computation optimization.
> This update disables a specific optimization in our LuaJIT fork that could
> potentially lead to performance degradation under certain circumstances
> (CVE-2024-39702).
> >
> > It's important to note that this issue is specific to our OpenResty
> branch of LuaJIT and does not affect the upstream mainline LuaJIT.
> >
> > We would like to express our gratitude to Zhongwei Yao from Kong INC.
> for reporting this issue.
> >
> > The full announcement, download links, and change logs can be found
> below:
> >
> > http://openresty.org/en/ann-1025003002.html
> >
> > You can download the software packages here:
> >
> > https://openresty.org/en/download.html
> >
> > OpenResty is a high performance and dynamic web platform based on our
> enhanced version of Nginx core, our enhanced version of LuaJIT, and many
> powerful Nginx modules and Lua libraries. See OpenResty's homepage for
> details:
> >
> > https://openresty.org/en/
> >
> > We strongly recommend all users to upgrade to this version to ensure
> optimal performance and security.
> >
> > OpenResty Inc. provides commercial support and private module
> development for the open-source OpenResty. For more information, please
> visit https://openresty.com.
> >
> > Enjoy!
> >
> > Best regards,
> > Jiahao
> > _______________________________________________
> > nginx mailing list
> > nginx@nginx.org
> > https://mailman.nginx.org/mailman/listinfo/nginx
> _______________________________________________
> nginx mailing list
> nginx@nginx.org
> https://mailman.nginx.org/mailman/listinfo/nginx
>
_______________________________________________
nginx mailing list
nginx@nginx.org
https://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

[ANN] OpenResty 1.25.3.2 released

Jiahao Wang via nginx July 22, 2024 03:48AM

Re: [ANN] OpenResty 1.25.3.2 released

Lucas Rolff July 22, 2024 04:06AM

Re: [ANN] OpenResty 1.25.3.2 released

Mathew Heard July 22, 2024 04:10AM

Re: [ANN] OpenResty 1.25.3.2 released

Jiahao Wang via nginx July 22, 2024 04:46AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 106
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 500 on July 15, 2024
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready