Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Fedora 38: 2024-1249d56928 Critical: Insecure Shared Memory Issue

fedora
Calendar Grey April 17, 2024
Dist Fedora Esm H88
The release of Mbedtls 2.28.8 in Fedora 38 tackles vulnerabilities related to the secure management of shared memory resources.
Update to 2.28.8 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.8

Summary

Mbed TLS is a light-weight open source cryptographic and SSL/TLS

library written in C. Mbed TLS makes it easy for developers to include

cryptographic and SSL/TLS capabilities in their (embedded)

applications with as little hassle as possible.

Update Information:

Update to 2.28.8 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.8

Change Log

* Mon Apr 1 2024 Morten Stevens - 2.28.8-1 - Update to 2.28.8

References


[ 1 ] Bug #2272172 - CVE-2024-28960 mbedtls: Insecure handling of shared memory in PSA Crypto APIs https://bugzilla.redhat.com/show_bug.cgi?id=2272172

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-1249d56928' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mbedtls
Product: Fedora 38
Version: 2.28.8
Release: 1.fc38
Summary: Light-weight cryptographic and SSL/TLS library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here