Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Oracle Linux 9 ELSA-2022-6854 Moderate: Gnutls And Nettle Update

oracle
Calendar Grey October 11, 2022
Oracle Linux Logo Esm H88
Oracle Linux Security Advisory ELSA-2022-6854 outlines critical updates for vulnerabilities in gnutls and nettle, stressing the need for timely patch application to maintain security.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

gnutls [3.7.6-12] - fips: mark PBKDF2 with short key and output sizes non-approved - fips: only mark HMAC as approved in PBKDF2 - fips: mark gnutls_key_generate with short key sizes non-approved - fips: fix checking on hash algorithm used in ECDSA - fips: preserve operation context around FIPS selftests API [3.7.6-11] - Supply --with{,out}-{zlib,brotli,zstd} explicitly [3.7.6-10] - Revert nettle version pinning as it doesn't work well in side-tag [3.7.6-9] - Pin nettle version in Requires when compiled with FIPS [3.7.6-8] - Bundle GMP to privatize memory functions - Disable certificate compression support by default [3.7.6-7] - Update gnutls-3.7.6-cpuid-fixes.patch [3.7.6-6] - Mark RSA SigVer operation approved for known modulus sizes (#2119770) - accelerated: clear AVX bits if it cannot be queried through XSAVE [3.7.6-5] - Block DES-CBC usage in decrypting PKCS#12 bag under FIPS (#2115314) - sysrng: reseed source DRBG for prediction resistance [3.7.6-4] - Make gnutls-cli w...

Read the Full Advisory

SRPMs

https://oss.oracle.com:443/ol9/SRPMS-updates/gnutls-3.7.6-12.el9_0.src.rpm https://oss.oracle.com:443/ol9/SRPMS-updates/nettle-3.8-3.el9_0.src.rpm

x86_64

gnutls-3.7.6-12.el9_0.i686.rpm gnutls-3.7.6-12.el9_0.x86_64.rpm gnutls-c++-3.7.6-12.el9_0.i686.rpm gnutls-c++-3.7.6-12.el9_0.x86_64.rpm gnutls-dane-3.7.6-12.el9_0.i686.rpm gnutls-dane-3.7.6-12.el9_0.x86_64.rpm gnutls-devel-3.7.6-12.el9_0.i686.rpm gnutls-devel-3.7.6-12.el9_0.x86_64.rpm gnutls-utils-3.7.6-12.el9_0.x86_64.rpm nettle-3.8-3.el9_0.i686.rpm nettle-3.8-3.el9_0.x86_64.rpm nettle-devel-3.8-3.el9_0.i686.rpm nettle-devel-3.8-3.el9_0.x86_64.rpm

aarch64

gnutls-3.7.6-12.el9_0.aarch64.rpm gnutls-c++-3.7.6-12.el9_0.aarch64.rpm gnutls-dane-3.7.6-12.el9_0.aarch64.rpm gnutls-devel-3.7.6-12.el9_0.aarch64.rpm gnutls-utils-3.7.6-12.el9_0.aarch64.rpm nettle-3.8-3.el9_0.aarch64.rpm nettle-devel-3.8-3.el9_0.aarch64.rpm

Related CVEs: CVE-2022-2509

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here