MGASA-2024-0037 - Updated mbedtls packages fix security vulnerabilities

Publication date: 14 Feb 2024
URL: https://advisories.mageia.org/MGASA-2024-0037.html
Type: security
Affected Mageia releases: 9

This update brings the mbedtls packages from 2.28.3 to the latest 2.28.7
release in the LTS branch, fixing a number of bugs as well the following
security vulnerabilities:
- Buffer overread in TLS stream cipher suites.
- Timing side channel in private key RSA operations.
- Buffer overflow in mbedtls_x509_set_extension.
See the linked release notes for details.

References:
- https://bugs.mageia.org/show_bug.cgi?id=32844
- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.4
- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.5
- https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-2.28.5
- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.6
- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7
- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2023-10-1/
- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-1/
- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/

SRPMS:
- 9/core/mbedtls-2.28.7-1.mga9

Mageia 2024-0037: mbedtls security update

This update brings the mbedtls packages from 2.28.3 to the latest 2.28.7 release in the LTS branch, fixing a number of bugs as well the following security vulnerabilities: - Buffer...

Summary

This update brings the mbedtls packages from 2.28.3 to the latest 2.28.7 release in the LTS branch, fixing a number of bugs as well the following security vulnerabilities: - Buffer overread in TLS stream cipher suites. - Timing side channel in private key RSA operations.

References

- https://bugs.mageia.org/show_bug.cgi?id=32844

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.4

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.5

- https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-2.28.5

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.6

- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7

- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2023-10-1/

- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-1/

- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/

Resolution

MGASA-2024-0037 - Updated mbedtls packages fix security vulnerabilities

SRPMS

- 9/core/mbedtls-2.28.7-1.mga9

Severity
Publication date: 14 Feb 2024
URL: https://advisories.mageia.org/MGASA-2024-0037.html
Type: security

Related News