Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 39: FEDORA-2024-bfd98be425 Critical: mbedtls Multiple Threats

fedora
Calendar Grey February 17, 2024
Dist Fedora Esm H88
Fedora 39 Release Alert concerning mbedtls 2.28.7 highlights critical vulnerabilities. Visit for comprehensive update notes and guidance.
Update to 2.28.7 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7 Security Advisories: -

Summary

Mbed TLS is a light-weight open source cryptographic and SSL/TLS

library written in C. Mbed TLS makes it easy for developers to include

cryptographic and SSL/TLS capabilities in their (embedded)

applications with as little hassle as possible.

Update Information:

Update to 2.28.7 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7 Security Advisories: - advisory-2024-01-1/ - advisory-2024-01-2/

Change Log

* Tue Feb 6 2024 Morten Stevens - 2.28.7-1 - Update to 2.28.7 * Tue Feb 6 2024 Morten Stevens - 2.28.5-4 - Disabled testing due to build issues with GCC 14 * Thu Jan 25 2024 Fedora Release Engineering - 2.28.5-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 2.28.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2261600 - CVE-2024-23170 CVE-2024-23775 mbedtls: multiple vulnerabilties [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2261600

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-bfd98be425' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mbedtls
Product: Fedora 39
Version: 2.28.7
Release: 1.fc39
Summary: Light-weight cryptographic and SSL/TLS library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here