Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update for gnutls and nettle is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: gnutls and nettle security, bug fix, and enhancement update Advisory ID: RHSA-2022:6854-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:6854 Issue date: 2022-10-11 CVE Names: CVE-2022-2509 ==================================================================== 1. Summary: An update for gnutls and nettle is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Nettle is a cryptographic library that is designed to fit easily in almost any context: In crypto toolkits for object-oriented languages, such as C++, Python, or Pike, in applications like LSH or GNUPG, or even in kernel space. The following packages have been upgraded to a later upstream version: gnutls (3.7.6), nettle (3.8). Security Fix(es): * gnutls: Double free during gnutls_pkcs7_verify. (CVE-2022-2509) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information,refer to the CVE page(s) listed in the References section. Bug Fix(es): * [IBM 9.1] [P10] POWER10 performance enhancements for cryptography: nettle - - incremental work (BZ#2102589) * Allow enabling KTLS in RHEL 9.1 (BZ#2108532) * DES-CBC bag is decryptable under FIPS (BZ#2115314) * allow signature verification using RSA keys
Moderate: gnutls and nettle security, bug fix, and enhancement update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:4451', 'synopsis': 'Moderate: gnutls and nettle security, bug fix, and enhancement update', 'severity': 'Moderate', 'topic': 'An update for gnutls and nettle is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.\nNettle is a cryptographic library that is designed to fit easily in almost any context: In crypto toolkits for object-oriented languages, such as C++, Python, or Pike, in applications like LSH or GNUPG, or even in kernel space.\nThe following packages have been upgraded to a later upstream version: gnutls (3.6.16). (BZ#1956783)\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1776250', '1908110', '1908334', '1922275', '1922276', '1965445', '1967983'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-3580.json:::CVE-2021-3580'], 'references': [], 'publishedAt': '2022-08-29T22:14:11.345724Z', 'rpms': ['gnutls-3.6.16-4.el8.aarch64.rpm', 'gnutls-3.6.16-4.el8.i686.rpm', 'gnutls-3.6.16-4.el8.src.rpm', 'gnutls-3.6.16-4.el8.x86_64.rpm', 'gnutls-c++-3.6.16-4.el8.aarch64.rpm', 'gnutls-c++-3.6.16-4.el8.i686.rpm', 'gnutls-c++-3.6.16-4.el8.x86_64.rpm','gnutls-c++-debuginfo-3.6.16-4.el8.aarch64.rpm', 'gnutls-c++-debuginfo-3.6.16-4.el8.i686.rpm', 'gnutls-c++-debuginfo-3.6.16-4.el8.x86_64.rpm', 'gnutls-dane-3.6.16-4.el8.aarch64.rpm', 'gnutls-dane-3.6.16-4.el8.i686.rpm', 'gnutls-dane-3.6.16-4.el8.x86_64.rpm', 'gnutls-dane-debuginfo-3.6.16-4.el8.aarch64.rpm', 'gnutls-dane-debuginfo-3.6.16-4.el8.i686.rpm', 'gnutls-dane-debuginfo-3.6.16-4.el8.x86_64.rpm', 'gnutls-debuginfo-3.6.16-4.el8.aarch64.rpm', 'gnutls-debuginfo-3.6.16-4.el8.i686.rpm', 'gnutls-debuginfo-3.6.16-4.el8.x86_64.rpm', 'gnutls-debugsource-3.6.16-4.el8.aarch64.rpm', 'gnutls-debugsource-3.6.16-4.el8.i686.rpm', 'gnutls-debugsource-3.6.16-4.el8.x86_64.rpm', 'gnutls-devel-3.6.16-4.el8.aarch64.rpm', 'gnutls-devel-3.6.16-4.el8.i686.rpm', 'gnutls-devel-3.6.16-4.el8.x86_64.rpm', 'gnutls-utils-3.6.16-4.el8.aarch64.rpm', 'gnutls-utils-3.6.16-4.el8.x86_64.rpm', 'gnutls-utils-debuginfo-3.6.16-4.el8.aarch64.rpm', 'gnutls-utils-debuginfo-3.6.16-4.el8.x86_64.rpm', 'nettle-3.4.1-7.el8.aarch64.rpm', 'nettle-3.4.1-7.el8.i686.rpm', 'nettle-3.4.1-7.el8.src.rpm', 'nettle-3.4.1-7.el8.x86_64.rpm', 'nettle-debuginfo-3.4.1-7.el8.aarch64.rpm', 'nettle-debuginfo-3.4.1-7.el8.i686.rpm', 'nettle-debuginfo-3.4.1-7.el8.x86_64.rpm', 'nettle-debugsource-3.4.1-7.el8.aarch64.rpm', 'nettle-debugsource-3.4.1-7.el8.i686.rpm', 'nettle-debugsource-3.4.1-7.el8.x86_64.rpm', 'nettle-devel-3.4.1-7.el8.aarch64.rpm', 'nettle-devel-3.4.1-7.el8.i686.rpm', 'nettle-devel-3.4.1-7.el8.x86_64.rpm']}\. An essential upgrade for gnutls and nettle on Rocky Linux 8 has been released, aimed at resolving vulnerabilities and delivering performance improvements.. Gnutls Update, Nettle Update, Rocky Linux Security Fixes. . LinuxSecurity.com Team
An update for gnutls and nettle is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: gnutls and nettle security, bug fix, and enhancement update Advisory ID: RHSA-2021:4451-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4451 Issue date: 2021-11-09 CVE Names: CVE-2021-3580 CVE-2021-20231 CVE-2021-20232 ==================================================================== 1. Summary: An update for gnutls and nettle is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Nettle is a cryptographic library that is designed to fit easily in almost any context: In crypto toolkits for object-oriented languages, such as C++, Python, or Pike, in applications like LSH or GNUPG, or even in kernel space. The following packages have been upgraded to a later upstream version: gnutls (3.6.16). (BZ#1956783) Security Fix(es): * nettle: Remote crash in RSA decryption via manipulated ciphertext (CVE-2021-3580) * gnutls: Use after free in client key_share extension (CVE-2021-20231) *gnutls: Use after free in client_send_params in lib/ext/pre_shared_key.c (CVE-2021-20232) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1776250 - p11tool do not reuse ID for certificate matching ECDSA private key when importing to PKCS#11 device 1908110 - gnutls update 3.6.14-7.el8_3 includes time BOMB in tests 1908334 - gnutls-serv doesn't listen on IPvN loopback addresses if there are no IPvN external addresses configured 1922275 - CVE-2021-20232 gnutls: Use after free in client_send_params in lib/ext/pre_shared_key.c 1922276 - CVE-2021-20231 gnutls: Use after free in client key_share extension 1965445 - SHA-1 CAs are rejected even if they are explicitly trusted 1967983 - CVE-2021-3580 nettle: Remote crash in RSA decryption via manipulated ciphertext 6. Package List: Red Hat Enterprise Linux AppStream (v.8): aarch64: gnutls-c++-3.6.16-4.el8.aarch64.rpm gnutls-c++-debuginfo-3.6.16-4.el8.aarch64.rpm gnutls-dane-3.6.16-4.el8.aarch64.rpm gnutls-dane-debuginfo-3.6.16-4.el8.aarch64.rpm gnutls-debuginfo-3.6.16-4.el8.aarch64.rpm gnutls-debugsource-3.6.16-4.el8.aarch64.rpm gnutls-devel-3.6.16-4.el8.aarch64.rpm gnutls-utils-3.6.16-4.el8.aarch64.rpm gnutls-utils-debuginfo-3.6.16-4.el8.aarch64.rpm nettle-debuginfo-3.4.1-7.el8.aarch64.rpm nettle-debugsource-3.4.1-7.el8.aarch64.rpm nettle-devel-3.4.1-7.el8.aarch64.rpm ppc64le: gnutls-c++-3.6.16-4.el8.ppc64le.rpm gnutls-c++-debuginfo-3.6.16-4.el8.ppc64le.rpm gnutls-dane-3.6.16-4.el8.ppc64le.rpm gnutls-dane-debuginfo-3.6.16-4.el8.ppc64le.rpm gnutls-debuginfo-3.6.16-4.el8.ppc64le.rpm gnutls-debugsource-3.6.16-4.el8.ppc64le.rpm gnutls-devel-3.6.16-4.el8.ppc64le.rpm gnutls-utils-3.6.16-4.el8.ppc64le.rpm gnutls-utils-debuginfo-3.6.16-4.el8.ppc64le.rpm nettle-debuginfo-3.4.1-7.el8.ppc64le.rpm nettle-debugsource-3.4.1-7.el8.ppc64le.rpm nettle-devel-3.4.1-7.el8.ppc64le.rpm s390x: gnutls-c++-3.6.16-4.el8.s390x.rpm gnutls-c++-debuginfo-3.6.16-4.el8.s390x.rpm gnutls-dane-3.6.16-4.el8.s390x.rpm gnutls-dane-debuginfo-3.6.16-4.el8.s390x.rpm gnutls-debuginfo-3.6.16-4.el8.s390x.rpm gnutls-debugsource-3.6.16-4.el8.s390x.rpm gnutls-devel-3.6.16-4.el8.s390x.rpm gnutls-utils-3.6.16-4.el8.s390x.rpm gnutls-utils-debuginfo-3.6.16-4.el8.s390x.rpm nettle-debuginfo-3.4.1-7.el8.s390x.rpm nettle-debugsource-3.4.1-7.el8.s390x.rpm nettle-devel-3.4.1-7.el8.s390x.rpm x86_64: gnutls-c++-3.6.16-4.el8.i686.rpm gnutls-c++-3.6.16-4.el8.x86_64.rpm gnutls-c++-debuginfo-3.6.16-4.el8.i686.rpm gnutls-c++-debuginfo-3.6.16-4.el8.x86_64.rpm gnutls-dane-3.6.16-4.el8.i686.rpm gnutls-dane-3.6.16-4.el8.x86_64.rpm gnutls-dane-debuginfo-3.6.16-4.el8.i686.rpm gnutls-dane-debuginfo-3.6.16-4.el8.x86_64.rpm gnutls-debuginfo-3.6.16-4.el8.i686.rpm gnutls-debuginfo-3.6.16-4.el8.x86_64.rpm gnutls-debugsource-3.6.16-4.el8.i686.rpm gnutls-debugsource-3.6.16-4.el8.x86_64.rpm gnutls-devel-3.6.16-4.el8.i686.rpm gnutls-devel-3.6.16-4.el8.x86_64.rpm gnutls-utils-3.6.16-4.el8.x86_64.rpm gnutls-utils-debuginfo-3.6.16-4.el8.i686.rpm gnutls-utils-debuginfo-3.6.16-4.el8.x86_64.rpm nettle-debuginfo-3.4.1-7.el8.i686.rpm nettle-debuginfo-3.4.1-7.el8.x86_64.rpm nettle-debugsource-3.4.1-7.el8.i686.rpm nettle-debugsource-3.4.1-7.el8.x86_64.rpm nettle-devel-3.4.1-7.el8.i686.rpm nettle-devel-3.4.1-7.el8.x86_64.rpm Red Hat Enterprise Linux BaseOS (v.8): Source: gnutls-3.6.16-4.el8.src.rpm nettle-3.4.1-7.el8.src.rpm aarch64: gnutls-3.6.16-4.el8.aarch64.rpm gnutls-c++-debuginfo-3.6.16-4.el8.aarch64.rpm gnutls-dane-debuginfo-3.6.16-4.el8.aarch64.rpm gnutls-debuginfo-3.6.16-4.el8.aarch64.rpm gnutls-debugsource-3.6.16-4.el8.aarch64.rpm gnutls-utils-debuginfo-3.6.16-4.el8.aarch64.rpm nettle-3.4.1-7.el8.aarch64.rpm nettle-debuginfo-3.4.1-7.el8.aarch64.rpm nettle-debugsource-3.4.1-7.el8.aarch64.rpm ppc64le: gnutls-3.6.16-4.el8.ppc64le.rpm gnutls-c++-debuginfo-3.6.16-4.el8.ppc64le.rpm gnutls-dane-debuginfo-3.6.16-4.el8.ppc64le.rpm gnutls-debuginfo-3.6.16-4.el8.ppc64le.rpm gnutls-debugsource-3.6.16-4.el8.ppc64le.rpm gnutls-utils-debuginfo-3.6.16-4.el8.ppc64le.rpm nettle-3.4.1-7.el8.ppc64le.rpm nettle-debuginfo-3.4.1-7.el8.ppc64le.rpm nettle-debugsource-3.4.1-7.el8.ppc64le.rpm s390x: gnutls-3.6.16-4.el8.s390x.rpm gnutls-c++-debuginfo-3.6.16-4.el8.s390x.rpm gnutls-dane-debuginfo-3.6.16-4.el8.s390x.rpm gnutls-debuginfo-3.6.16-4.el8.s390x.rpm gnutls-debugsource-3.6.16-4.el8.s390x.rpm gnutls-utils-debuginfo-3.6.16-4.el8.s390x.rpm nettle-3.4.1-7.el8.s390x.rpm nettle-debuginfo-3.4.1-7.el8.s390x.rpm nettle-debugsource-3.4.1-7.el8.s390x.rpm x86_64: gnutls-3.6.16-4.el8.i686.rpm gnutls-3.6.16-4.el8.x86_64.rpm gnutls-c++-debuginfo-3.6.16-4.el8.i686.rpm gnutls-c++-debuginfo-3.6.16-4.el8.x86_64.rpm gnutls-dane-debuginfo-3.6.16-4.el8.i686.rpm gnutls-dane-debuginfo-3.6.16-4.el8.x86_64.rpm gnutls-debuginfo-3.6.16-4.el8.i686.rpm gnutls-debuginfo-3.6.16-4.el8.x86_64.rpm gnutls-debugsource-3.6.16-4.el8.i686.rpm gnutls-debugsource-3.6.16-4.el8.x86_64.rpm gnutls-utils-debuginfo-3.6.16-4.el8.i686.rpm gnutls-utils-debuginfo-3.6.16-4.el8.x86_64.rpm nettle-3.4.1-7.el8.i686.rpm nettle-3.4.1-7.el8.x86_64.rpm nettle-debuginfo-3.4.1-7.el8.i686.rpm nettle-debuginfo-3.4.1-7.el8.x86_64.rpm nettle-debugsource-3.4.1-7.el8.i686.rpm nettle-debugsource-3.4.1-7.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-3580 https://access.redhat.com/security/cve/CVE-2021-20231 https://access.redhat.com/security/cve/CVE-2021-20232 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.5_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYYrd89zjgjWX9erEAQgvABAAk5lcKW4xz1CTb3A496iCBhayANX6Pp7v HMtFQSk6Naf/5dKhbsVjAci7DI3J2oWff3XldSCzS6fRkdgb0n0O9R4DcCHMpEAu yMsZ3UFfxt+lcdQzHhCdGcGTkeL895JJrGZLsIplTp5BAgAyxOMRJ3Kh1bTnvcT3 kfQfZT4Az2k3tG8bSRLiMPIT3Rd9vqxWBaHtXQGXpNTMz74RmydRentOrbkXXfmt jP+zXTA3UBp6zvzZoIsr5gaxfAzPadtriMQhr5wQNcveq2uhWdUnMuknQWgvb/Ci JproqBcqrGDfDts+EVmnvfwZeZvBetupy7EqiUGDWqosayDE1dPgdDMeUJAda7F2 TchdKCwWVe2c4bGLSN/VQw7PKJw94MUxd/1fbZpWA0FHeHHzxcy9d6zW1wbZ4jib 0hGGJPi2UmH4rIDbpH4gLxB/FFghLv3wNfzl5QVuRsrJDO+yYseh6tA0/N8BMQU1 X2OfbMYiDDr2ui1j87jj8Gtq1sYp7TzJk15/cFSfDCoRTRI5vE/POsWc169OO37q RnaE0MIiX0Re0V4548GmA5W/LeBlv/z06uvzSavZPHfIr4BY2O6zZHXeViW2dQLM E9QoYetu0hJ7t316P1Q4AZlzY4wr0wkUwtHDWkd9f7WgSYY9+OPQ2mfxgrcTEQw8 vqBF3aui7yY=6kIz -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures. . -------------------------------------------------------------------------Debian LTS Advisory DLA-2760-1
An update for nettle is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nettle security update Advisory ID: RHSA-2021:2758-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2758 Issue date: 2021-07-15 CVE Names: CVE-2021-20305 ==================================================================== 1. Summary: An update for nettle is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server E4S (v. 7.4) - ppc64le, x86_64 Red Hat Enterprise Linux Server TUS (v. 7.4) - x86_64 3. Description: Nettle is a cryptographic library that is designed to fit easily in almost any context: In crypto toolkits for object-oriented languages, such as C++, Python, or Pike, in applications like LSH or GNUPG, or even in kernel space. Security Fix(es): * nettle: Out of bounds memory access in signature verification (CVE-2021-20305) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, whichincludes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1942533 - CVE-2021-20305 nettle: Out of bounds memory access in signature verification 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.4): Source: nettle-2.7.1-9.el7_4.src.rpm x86_64: nettle-2.7.1-9.el7_4.i686.rpm nettle-2.7.1-9.el7_4.x86_64.rpm nettle-debuginfo-2.7.1-9.el7_4.i686.rpm nettle-debuginfo-2.7.1-9.el7_4.x86_64.rpm nettle-devel-2.7.1-9.el7_4.i686.rpm nettle-devel-2.7.1-9.el7_4.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.4): Source: nettle-2.7.1-9.el7_4.src.rpm ppc64le: nettle-2.7.1-9.el7_4.ppc64le.rpm nettle-debuginfo-2.7.1-9.el7_4.ppc64le.rpm nettle-devel-2.7.1-9.el7_4.ppc64le.rpm x86_64: nettle-2.7.1-9.el7_4.i686.rpm nettle-2.7.1-9.el7_4.x86_64.rpm nettle-debuginfo-2.7.1-9.el7_4.i686.rpm nettle-debuginfo-2.7.1-9.el7_4.x86_64.rpm nettle-devel-2.7.1-9.el7_4.i686.rpm nettle-devel-2.7.1-9.el7_4.x86_64.rpm Red Hat Enterprise Linux Server TUS (v. 7.4): Source: nettle-2.7.1-9.el7_4.src.rpm x86_64: nettle-2.7.1-9.el7_4.i686.rpm nettle-2.7.1-9.el7_4.x86_64.rpm nettle-debuginfo-2.7.1-9.el7_4.i686.rpm nettle-debuginfo-2.7.1-9.el7_4.x86_64.rpm nettle-devel-2.7.1-9.el7_4.i686.rpm nettle-devel-2.7.1-9.el7_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-20305 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYPCGZtzjgjWX9erEAQgaQQ//UVjg5ptMbKk1ULc/iUcjXPyoFMXMg+Ta YNd6429vOJ5/NhsaiIyYrJZE01dVtOVBtwqGr88KJD5kqAyBA0eLOxzut7thXHdI 7kTmJ90TxxljM7l+w8kNzmHuln20jhCwHtCsqRESfOLsaL9NApyaUfPutG4dYlzw Wo7pHOtxcHAslrN05LdxSSWDfIbha+GrtRXVzh+1jxJnmHZV0AJENDnp4SxB2GN+ Jw7+jaE5B9Q4M2lQexnUWDcXS4HeigOLn+iNfOtVa8Q2m2pwxUf8dKVefQJA5jZy WVFzsrxJZQTKoEINtPFFnUL0utI8A6HhC1Si6xi7kJUE/1kQqzRaLDqydStyrEZd AWuAScwu+jclaNKaCoZE1cfFlRIMMUYxVOZUGAGw5KYiEQI2tNe9xk+Wg94cWkP2 22RbX/NEbeYknJiUAbt8jSx4wX/Juv3VUrL8ya5IlUJrnZ6M8r+ZEEXra1HlUAfJ GfpZKAxaG0AKXVaaGNCiwbYbUuuyh1H6+/JIn9k4pa5YJjwnN384vfDCYoZVckdS o40jzdN2kYmgJLweK6/KBeI5IZAoXnOrHFwwFsKPxaaJSYjfOteNHvRCuX0apYYQ yLtY1NiSHYRlZ50huVM9ZHhNzPOQOaR9GhZ1zSYtRjhF+Z80bQQEXwC7yQHA1ORE 548n7psxtRE=/jmk -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Several security issues were fixed in Nettle.. =========================================================================Ubuntu Security Notice USN-4990-1 June 17, 2021 nettle vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Nettle. Software Description: - nettle: low level cryptographic library Details: It was discovered that Nettle incorrectly handled RSA decryption. A remote attacker could possibly use this issue to cause Nettle to crash, resulting in a denial of service. (CVE-2021-3580) It was discovered that Nettle incorrectly handled certain padding oracles. A remote attacker could possibly use this issue to perform a variant of the Bleichenbacher attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-16869) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: libnettle8 3.7-2.1ubuntu1.1 Ubuntu 20.10: libnettle8 3.6-2ubuntu0.2 Ubuntu 20.04 LTS: libnettle7 3.5.1+really3.5.1-2ubuntu0.2 Ubuntu 18.04 LTS: libnettle6 3.4.1-0ubuntu0.18.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4990-1 CVE-2018-16869, CVE-2021-3580 Package Information: https://launchpad.net/ubuntu/+source/nettle/3.7-2.1ubuntu1.1 https://launchpad.net/ubuntu/+source/nettle/3.6-2ubuntu0.2 https://launchpad.net/ubuntu/+source/nettle/3.5.1+really3.5.1-2ubuntu0.2 https://launchpad.net/ubuntu/+source/nettle/3.4.1-0ubuntu0.18.04.1 . Nettle patches for several Ubuntu distributions resolve critical vulnerabilities, such as potential remote denial of service threats.. Nettle Issues, UbuntuSecurity Patches, Cryptographic Library, Remote Threats. . Severity: Important. LinuxSecurity.com Team
The package nettle before version 3.7.3-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-202106-28 ========================================= Severity: Medium Date : 2021-06-09 CVE-ID : CVE-2021-3580 Package : nettle Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-2052 Summary ====== The package nettle before version 3.7.3-1 is vulnerable to denial of service. Resolution ========= Upgrade to 3.7.3-1. # pacman -Syu "nettle> =3.7.3-1" The problem has been fixed upstream in version 3.7.3. Workaround ========= None. Description ========== Multiple issues were found with Nettle's RSA decryption functions before version 3.7.3. These can be triggered by providing manipulated ciphertext and could lead to application crash and denial of service. Since nettle is used with gnuTLS, there is a possibility that a remote client could crash a server compiled with gnuTLS when RSA is used for the initial key exchange. Impact ===== A remote attacker could crash an application using Nettle with a crafted RSA ciphertext. References ========= https://bugzilla.redhat.com/show_bug.cgi?id=1967983 https://git.lysator.liu.se/nettle/nettle/-/commit/0ad0b5df315665250dfdaa4a1e087f4799edaefe https://git.lysator.liu.se/nettle/nettle/-/commit/485b5e2820a057e873b1ba812fdb39cae4adf98c https://security.archlinux.org/CVE-2021-3580 . Fedorian Security Note FSA-202206-45 informs about a low severity vulnerability in gmp prior to version 6.2.1-2.. Nettle Security, Arch Linux Advisory, Denial of Service Threats. . Severity: Medium. LinuxSecurity.com Team
An update for nettle is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nettle security update Advisory ID: RHSA-2021:2280-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2280 Issue date: 2021-06-07 CVE Names: CVE-2021-20305 ==================================================================== 1. Summary: An update for nettle is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64 3. Description: Nettle is a cryptographic library that is designed to fit easily in almost any context: In crypto toolkits for object-oriented languages, such as C++, Python, or Pike, in applications like LSH or GNUPG, or even in kernel space. Security Fix(es): * nettle: Out of bounds memory access in signature verification (CVE-2021-20305) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1942533 - CVE-2021-20305 nettle: Out of bounds memory access in signature verification 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7): Source: nettle-2.7.1-9.el7_7.src.rpm x86_64: nettle-2.7.1-9.el7_7.i686.rpm nettle-2.7.1-9.el7_7.x86_64.rpm nettle-debuginfo-2.7.1-9.el7_7.i686.rpm nettle-debuginfo-2.7.1-9.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7): x86_64: nettle-debuginfo-2.7.1-9.el7_7.i686.rpm nettle-debuginfo-2.7.1-9.el7_7.x86_64.rpm nettle-devel-2.7.1-9.el7_7.i686.rpm nettle-devel-2.7.1-9.el7_7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.7): Source: nettle-2.7.1-9.el7_7.src.rpm ppc64: nettle-2.7.1-9.el7_7.ppc.rpm nettle-2.7.1-9.el7_7.ppc64.rpm nettle-debuginfo-2.7.1-9.el7_7.ppc.rpm nettle-debuginfo-2.7.1-9.el7_7.ppc64.rpm nettle-devel-2.7.1-9.el7_7.ppc.rpm nettle-devel-2.7.1-9.el7_7.ppc64.rpm ppc64le: nettle-2.7.1-9.el7_7.ppc64le.rpm nettle-debuginfo-2.7.1-9.el7_7.ppc64le.rpm nettle-devel-2.7.1-9.el7_7.ppc64le.rpm s390x: nettle-2.7.1-9.el7_7.s390.rpm nettle-2.7.1-9.el7_7.s390x.rpm nettle-debuginfo-2.7.1-9.el7_7.s390.rpm nettle-debuginfo-2.7.1-9.el7_7.s390x.rpm nettle-devel-2.7.1-9.el7_7.s390.rpm nettle-devel-2.7.1-9.el7_7.s390x.rpm x86_64: nettle-2.7.1-9.el7_7.i686.rpm nettle-2.7.1-9.el7_7.x86_64.rpm nettle-debuginfo-2.7.1-9.el7_7.i686.rpm nettle-debuginfo-2.7.1-9.el7_7.x86_64.rpm nettle-devel-2.7.1-9.el7_7.i686.rpm nettle-devel-2.7.1-9.el7_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-20305 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iQIVAwUBYL6eNtzjgjWX9erEAQh3WQ/+Il7VEBb9hVGaLYX+U4/aKbS8L/vrOo/i q0wUY2LLmKZhijN2TceW6qAbh4O9jPkeQjtmyIU8FGdtr0WwnyMSEo4wXLXhVkis kgBHfpQFpqaFXeQ30272LjIBf4XRTTP6wGHLtxXFS8sZ8aDfb0lS+ZiGVvFIOJw/ FFyBgFiAAgGg5gxtP8WmL9F9Di9u1fo1euM2IJCJGCCGbpWCs9smfuuzZcaRgM7T GmCTXvRd+Ee/9yXWOT+dVqB08BLYC2DZLG0qmz+SEzUxE+MxFna6BnYvnhYUi4Bi Nc0cjCZZz7fp5q4s0zHxPBuymhJkZOMIsCatVQ4hmWGfLvULgkGN4NdR815bX8lK Wp+4m6fFwfxhmZsz6+8chFHzxEclrtQZHWRyM4tI1SxaDBPKndTHh413FQXqGkvw JA2h4DzsJeX1ZbOfTdxk+3bXTFMN/R4Q8JG4OFnDLKoFYJWh8f7JiHB3/XgXVZOI Ipr0YTt0U0On3oXjDLwS++/azikW0dSaeQwVsK6WU7Rl2DbYoJgk0E97Xd4QDm80 4fGa27YFW00WnAxQEgYcKU4rUMWvYIpfG2O5XE7UzmeleS30QKbBKJwWyrKZTquW oiTNNodqO5lFVFmk0PhgkX7+lxpfbIwiz25FtkzAJ8kqz3lEGrkQER+3MEReU+ib ZTibuIAr/Yo=rIWK -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.