tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue ---- Fixed a context save and suspend/resume problem when public keys are loaded. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-8b584e5ebb 2021-03-19 19:51:22.363617 --------------------------------------------------------------------------------Name : libtpms Product : Fedora 34 Version : 0.8.2 Release : 0.20210301git729fc6a4ca.fc34.1 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. --------------------------------------------------------------------------------Update Information: tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue ----Fixed a context save and suspend/resume problem when public keys are loaded --------------------------------------------------------------------------------ChangeLog: * Mon Mar 1 2021 Stefan Berger - 0.8.2-0.20210301git729fc6a4ca - tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue * Sat Feb 27 2021 Stefan Berger - 0.8.1-0.20210227git5bf2746e47 - Fixed a context save and suspend/resume problem when public keys are loaded --------------------------------------------------------------------------------References: [ 1 ] Bug #1939665 - CVE-2021-3446 libtpms: return of wrong initialization vector when certain symmetric ciphers are used [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939665 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-8b584e5ebb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signedwith the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.