Updated mbedtls packages fix security vulnerabilities: If Mbed TLS is running in an SGX enclave and the adversary has control of the main operating system, they can launch a side channel attack to recover the RSA private key when it is being imported. Found by Alejandro . MGASA-2020-0130 - Updated mbedtls packages fix security vulnerabilities Publication date: 08 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0130.html Type: security Affected Mageia releases: 7 Updated mbedtls packages fix security vulnerabilities: If Mbed TLS is running in an SGX enclave and the adversary has control of the main operating system, they can launch a side channel attack to recover the RSA private key when it is being imported. Found by Alejandro Cabrera Aldaya and Billy Brumley and reported by Jack Lloyd. Fix potential memory overread when performing an ECDSA signature operation. The overread only happens with cryptographically low probability (of the order of 2^-n where n is the bitsize of the curve) unless the RNG is broken, and could result in information disclosure or denial of service (application crash or extra resource consumption). Found by Auke Zeilstra and Peter Schwabe, using static analysis. References: - https://bugs.mageia.org/show_bug.cgi?id=26259 - - https://www.trustedfirmware.org/projects/mbed-tls/ SRPMS: - 7/core/mbedtls-2.16.5-1.mga7 . Investigate MGASA-2020-0130 which relates to mbedtls revisions aimed at mitigating severe security threats and flaws.. mbedtls Update, Mageia Advisory, Security Risk, RSA Attack, Memory Overread. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.