Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Fedora 40: 2024-a23b5f0783 Critical: Mbedtls Insecure Handling Issue

fedora
Calendar Grey April 19, 2024
Dist Fedora Esm H88
The recent Mbedtls 2.28.8 update announcement for Fedora 40 tackles vulnerabilities, reinforcing encryption functionalities for improved security.
Update to 2.28.8 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.8

Summary

Mbed TLS is a light-weight open source cryptographic and SSL/TLS

library written in C. Mbed TLS makes it easy for developers to include

cryptographic and SSL/TLS capabilities in their (embedded)

applications with as little hassle as possible.

Update Information:

Update to 2.28.8 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.8

Change Log

* Mon Apr 1 2024 Morten Stevens - 2.28.8-1 - Update to 2.28.8

References


[ 1 ] Bug #2272172 - CVE-2024-28960 mbedtls: Insecure handling of shared memory in PSA Crypto APIs https://bugzilla.redhat.com/show_bug.cgi?id=2272172

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a23b5f0783' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mbedtls
Product: Fedora 40
Version: 2.28.8
Release: 1.fc40
Summary: Light-weight cryptographic and SSL/TLS library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here