OpenSSL Advisory: November 2nd, 2017 (BoringSSL Not Affected)

OpenSSL have published a security advisory. Here's how it affects BoringSSL:

CVESummarySeverity in OpenSSLImpact to BoringSSL
CVE-2017-3736bn_sqrx8x_internal carry bug on x86_64ModerateNot affected, affected code is not enabled in BoringSSL. See discussion below.
CVE-2017-3735Malformed X.509 IPAddressFamily could cause OOB readLowNot affected, affected code was removed in fork

CVE-2017-3736

The code was enabled briefly at BoringSSL head on 2017-08-14, but it was reverted 24 hours later when we learned of the bug.