iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: . MGASA-2024-0226 - Updated iperf packages fix security vulnerability Publication date: 17 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0226.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-26306 iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario. References: - https://bugs.mageia.org/show_bug.cgi?id=33296 - https://lists.suse.com/pipermail/sle-updates/2024-June/035556.html - https://www.cve.org/CVERecord?id=CVE-2024-26306 SRPMS: - 9/core/iperf-3.17.1-1.mga9 . Dive into the Mageia security notice MGASA-2024-0226, which focuses on iPerf3 upgrades to mitigate significant timing attack vulnerabilities.. Iperf3 Security Update, Mageia 9 Advisories, RSA Timing Attack, OpenSSL Vulnerability Fix, Credential Recovery Risk. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.