Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 9: Advisory MGASA-2024-0037 Critical: Mbedtls Vulnerabilities

mageia
Calendar Grey February 14, 2024
Dist Mageia Esm H88
Mageia release 2024-0038 rectifies openssl security issues by upgrading to version 1.1.1t, resolving identified defects and weaknesses.
This update brings the mbedtls packages from 2.28.3 to the latest 2.28.7 release in the LTS branch, fixing a number of bugs as well the following security vulnerabilities: - Buffer...

Summary

This update brings the mbedtls packages from 2.28.3 to the latest 2.28.7 release in the LTS branch, fixing a number of bugs as well the following security vulnerabilities: - Buffer overread in TLS stream cipher suites. - Timing side channel in private key RSA operations.

References

- https://bugs.mageia.org/show_bug.cgi?id=32844

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.4

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.5

- https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-2.28.5

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.6

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7

- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2023-10-1/

- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-1/

- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/

Resolution

SRPMS

- 9/core/mbedtls-2.28.7-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 14 Feb 2024
URL: https://advisories.mageia.org/MGASA-2024-0037.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here