Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
* bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607 . # Security update for openssl-3 Announcement ID: SUSE-SU-2025:1550-1 Release Date: 2025-05-14T17:05:27Z Rating: important References: * bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607 Cross-References: * CVE-2025-27587 CVSS scores: * CVE-2025-27587 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-27587 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has four security fixes can now be installed. ## Description: This update for openssl-3 fixes the following issues: Security: * CVE-2025-27587: Timing side channel vulnerability in the P-384 implementation when used with ECDSA in the PPC architecture (bsc#1240366). * Missing null pointer check before accessing handshake_func in ssl_lib.c (bsc#1240607). FIPS: * Disabling EMS in OpenSSL configuration prevents sshd from starting (bsc#1230959, bsc#1232326, bsc#1231748). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1550=1 openSUSE-SLE-15.6-2025-1550=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1550=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libopenssl3-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.27.1 * openssl-3-3.1.4-150600.5.27.1 * openssl-3-debuginfo-3.1.4-150600.5.27.1 *libopenssl-3-devel-3.1.4-150600.5.27.1 * openssl-3-debugsource-3.1.4-150600.5.27.1 * libopenssl3-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-3.1.4-150600.5.27.1 * openSUSE Leap 15.6 (x86_64) * libopenssl3-32bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-devel-32bit-3.1.4-150600.5.27.1 * libopenssl3-32bit-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.27.1 * openSUSE Leap 15.6 (noarch) * openssl-3-doc-3.1.4-150600.5.27.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl3-64bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-devel-64bit-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-64bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-64bit-3.1.4-150600.5.27.1 * libopenssl3-64bit-3.1.4-150600.5.27.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libopenssl3-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.27.1 * openssl-3-3.1.4-150600.5.27.1 * openssl-3-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-devel-3.1.4-150600.5.27.1 * openssl-3-debugsource-3.1.4-150600.5.27.1 * libopenssl3-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-3.1.4-150600.5.27.1 * Basesystem Module 15-SP6 (x86_64) * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.27.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl3-32bit-3.1.4-150600.5.27.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27587.html * https://bugzilla.suse.com/show_bug.cgi?id=1230959 * https://bugzilla.suse.com/show_bug.cgi?id=1231748 * https://bugzilla.suse.com/show_bug.cgi?id=1232326 * https://bugzilla.suse.com/show_bug.cgi?id=1240366 * https://bugzilla.suse.com/show_bug.cgi?id=1240607 . The recent OpenSSL-3 release for SUSE resolves a significant timing vulnerability and rectifies issuesassociated with sshd errors.. openssl update, SUSE security patch, important security advisory, timing issue fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one security fix can now be installed.. # Security update for openssl-1_1 Announcement ID: SUSE-SU-2025:0613-1 Release Date: 2025-02-21T10:38:08Z Rating: moderate References: * bsc#1236136 * bsc#1236771 Cross-References: * CVE-2024-13176 CVSS scores: * CVE-2024-13176 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-13176 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-13176 ( NVD ): 4.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L Affected Products: * Basesystem Module 15-SP6 * Development Tools Module 15-SP6 * Legacy Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for openssl-1_1 fixes the following issues: * CVE-2024-13176: Fixed timing side-channel in the ECDSA signature computation (bsc#1236136). Other bugfixes: * Non approved PBKDF parameters wrongly resulting as approved (bsc#1236771). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-613=1 openSUSE-SLE-15.6-2025-613=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-613=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-613=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-613=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libopenssl1_1-1.1.1w-150600.5.12.2 *libopenssl1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-1.1.1w-150600.5.12.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-debugsource-1.1.1w-150600.5.12.2 * libopenssl-1_1-devel-1.1.1w-150600.5.12.2 * openSUSE Leap 15.6 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1w-150600.5.12.2 * libopenssl1_1-32bit-1.1.1w-150600.5.12.2 * libopenssl-1_1-devel-32bit-1.1.1w-150600.5.12.2 * openSUSE Leap 15.6 (noarch) * openssl-1_1-doc-1.1.1w-150600.5.12.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl1_1-64bit-debuginfo-1.1.1w-150600.5.12.2 * libopenssl1_1-64bit-1.1.1w-150600.5.12.2 * libopenssl-1_1-devel-64bit-1.1.1w-150600.5.12.2 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libopenssl1_1-debuginfo-1.1.1w-150600.5.12.2 * libopenssl1_1-1.1.1w-150600.5.12.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-debugsource-1.1.1w-150600.5.12.2 * Basesystem Module 15-SP6 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1w-150600.5.12.2 * libopenssl1_1-32bit-1.1.1w-150600.5.12.2 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * openssl-1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-debugsource-1.1.1w-150600.5.12.2 * libopenssl-1_1-devel-1.1.1w-150600.5.12.2 * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1w-150600.5.12.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-1.1.1w-150600.5.12.2 ## References: * https://www.suse.com/security/cve/CVE-2024-13176.html * https://bugzilla.suse.com/show_bug.cgi?id=1236136 * https://bugzilla.suse.com/show_bug.cgi?id=1236771 . OpenSSL-1_1 security enhancement on 2025-02-21 resolves timing vulnerabilities and contains an update for SUSE.. OpenSSL Update, SUSE Security Advisory, Timing Side-Channel, Open Source Security, Package Update. . LinuxSecurity.com Team
* bsc#1217277 Cross-References: * CVE-2023-5981 . # Security update for gnutls Announcement ID: SUSE-SU-2023:4983-1 Rating: moderate References: * bsc#1217277 Cross-References: * CVE-2023-5981 CVSS scores: * CVE-2023-5981 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-5981 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for gnutls fixes the following issues: * CVE-2023-5981: Fixed timing side-channel inside RSA-PSK key exchange (bsc#1217277). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4983=1 SUSE-2023-4983=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-4983=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4983=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patchSUSE-SLE-Micro-5.4-2023-4983=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4983=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2023-4983=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4983=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4983=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libgnutlsxx-devel-3.7.3-150400.4.38.1 * libgnutlsxx28-3.7.3-150400.4.38.1 * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-guile-debuginfo-3.7.3-150400.4.38.1 * gnutls-guile-3.7.3-150400.4.38.1 * libgnutls-devel-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * openSUSE Leap 15.4 (x86_64) * libgnutls-devel-32bit-3.7.3-150400.4.38.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-32bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.38.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgnutls30-64bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-64bit-3.7.3-150400.4.38.1 * libgnutls-devel-64bit-3.7.3-150400.4.38.1 * libgnutls30-64bit-debuginfo-3.7.3-150400.4.38.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libgnutlsxx-devel-3.7.3-150400.4.38.1 * libgnutlsxx28-3.7.3-150400.4.38.1 * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 *libgnutlsxx28-debuginfo-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-guile-debuginfo-3.7.3-150400.4.38.1 * gnutls-guile-3.7.3-150400.4.38.1 * libgnutls-devel-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * openSUSE Leap 15.5 (x86_64) * libgnutls-devel-32bit-3.7.3-150400.4.38.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-32bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.38.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libgnutlsxx-devel-3.7.3-150400.4.38.1 * libgnutlsxx28-3.7.3-150400.4.38.1 * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * libgnutls-devel-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * Basesystem Module 15-SP4 (x86_64) *libgnutls30-32bit-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-32bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.38.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libgnutlsxx-devel-3.7.3-150400.4.38.1 * libgnutlsxx28-3.7.3-150400.4.38.1 * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * libgnutls-devel-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * Basesystem Module 15-SP5 (x86_64) * libgnutls30-32bit-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-32bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.38.1 ## References: * https://www.suse.com/security/cve/CVE-2023-5981.html * https://bugzilla.suse.com/show_bug.cgi?id=1217277 . SUSE announced a security update for gnutls addressing a timing side-channel flaw assessed with moderate risk.. Gnutls Update, Timing Side-Channel, Linux Security Update. . LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2160-1 Container Tags : bci/bci-base:15.4 , bci/bci-base:15.4.27.14.72 , suse/sle15:15.4 , suse/sle15:15.4.27.14.72 Container Release : 27.14.72 Severity : moderate Type : security References : 1201627 1207534 CVE-2022-4304 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2648-1 Released: Tue Jun 27 09:52:35 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1201627,1207534,CVE-2022-4304 This update for openssl-1_1 fixes the following issues: - CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption. The previous fix for this timing side channel turned out to cause a severe 2-3x performance regression in the typical use case (bsc#1207534). - Update further expiring certificates that affect the testsuite (bsc#1201627). The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150400.7.42.1 updated - libopenssl1_1-1.1.1l-150400.7.42.1 updated - openssl-1_1-1.1.1l-150400.7.42.1 updated . Routine security enhancement for suse/sle15 container features updates addressing openssl vulnerabilities and optimizations for better performance.. SUSE Container Update, Openssl Patch, Security Advisory. . LinuxSecurity.com Team
Release of gnutls 3.8.0 (fixes CVE-2023-0361) Release of gnutls guile bingings as standalone package.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-4fc4c33f2b 2023-03-18 05:00:58.357244 --------------------------------------------------------------------------------Name : guile-gnutls Product : Fedora 36 Version : 3.7.11 Release : 1.fc36 URL : https://gitlab.com/gnutls/guile Summary : Guile bindings for the GNUTLS library Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. This package contains Guile bindings for the library. --------------------------------------------------------------------------------Update Information: Release of gnutls 3.8.0 (fixes CVE-2023-0361) Release of gnutls guile bingings as standalone package. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 22 2023 Zoltan Fridrich - 3.7.11-1 - Initial import (fedora#2172108). --------------------------------------------------------------------------------References: [ 1 ] Bug #2168848 - gnutls-3.7.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2168848 [ 2 ] Bug #2169608 - CVE-2023-0361 gnutls: timing side-channel in the TLS RSA key exchange code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2169608 [ 3 ] Bug #2173612 - Error while performing self checks in FIPS mode https://bugzilla.redhat.com/show_bug.cgi?id=2173612 [ 4 ] Bug #2174758 - GNUTLS 3.8.0 changed ABI on i686 breaking all APIs using time_t https://bugzilla.redhat.com/show_bug.cgi?id=2174758 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-4fc4c33f2b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Release of gnutls 3.8.0 (fixes CVE-2023-0361) Release of gnutls guile bingings as standalone package.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-5b378b82b3 2023-03-14 00:16:44.046934 --------------------------------------------------------------------------------Name : guile-gnutls Product : Fedora 38 Version : 3.7.11 Release : 1.fc38 URL : https://gitlab.com/gnutls/guile Summary : Guile bindings for the GNUTLS library Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. This package contains Guile bindings for the library. --------------------------------------------------------------------------------Update Information: Release of gnutls 3.8.0 (fixes CVE-2023-0361) Release of gnutls guile bingings as standalone package. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 22 2023 Zoltan Fridrich - 3.7.11-1 - Initial import (fedora#2172108). --------------------------------------------------------------------------------References: [ 1 ] Bug #2168848 - gnutls-3.7.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2168848 [ 2 ] Bug #2169608 - CVE-2023-0361 gnutls: timing side-channel in the TLS RSA key exchange code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2169608 [ 3 ] Bug #2173612 - Error while performing self checks in FIPS mode https://bugzilla.redhat.com/show_bug.cgi?id=2173612 [ 4 ] Bug #2174758 - GNUTLS 3.8.0 changed ABI on i686 breaking all APIs using time_t https://bugzilla.redhat.com/show_bug.cgi?id=2174758 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-5b378b82b3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Moderate: gnutls security and bug fix update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1141", "synopsis": "Moderate: gnutls security and bug fix update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for gnutls.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.\n\nSecurity Fix(es):\n\n* gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* CCM tag length should be limited to known values (BZ#2144535)\n\n* In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator (BZ#2144537)\n\n* dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode (BZ#2149640)", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2144537", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2144537", "description": "* In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator"}, {"ticket": "2149640", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2149640", "description": "* dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode"}, {"ticket": "2162596", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162596", "description": ""}], "cves": [{"name": "CVE-2023-0361", "sourceBy": "MITRE","sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-0361", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-03-08T16:38:32.734709Z", "rpms": {"Rocky Linux 9": {"nvras": ["gnutls-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-0:3.7.6-18.el9_1.src.rpm", "gnutls-c++-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-c++-debuginfo-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-dane-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-dane-debuginfo-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-debuginfo-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-debugsource-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-devel-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-utils-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-utils-debuginfo-0:3.7.6-18.el9_1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux introduces a substantial OpenSSL maintenance and feature enhancement update, addressing critical vulnerabilities and reinforcing system security aspects.. Rocky Linux Security Update,GnuTLS Bug Fix, Linux Security Advisory,Gnutls Cryptography Patch. . LinuxSecurity.com Team
An update for gnutls is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: gnutls security and bug fix update Advisory ID: RHSA-2023:1141-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1141 Issue date: 2023-03-07 CVE Names: CVE-2023-0361 ==================================================================== 1. Summary: An update for gnutls is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): * gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * CCM tag length should be limited to known values (BZ#2144535) * In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide anindicator (BZ#2144537) * dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode (BZ#2149640) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2144537 - In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator [rhel-9.1.0.z] 2149640 - dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode [rhel-9.1.0.z] 2162596 - CVE-2023-0361 gnutls: timing side-channel in the TLS RSA key exchange code 6. Package List: Red Hat Enterprise Linux AppStream (v.9): aarch64: gnutls-c++-3.7.6-18.el9_1.aarch64.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-dane-3.7.6-18.el9_1.aarch64.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-debugsource-3.7.6-18.el9_1.aarch64.rpm gnutls-devel-3.7.6-18.el9_1.aarch64.rpm gnutls-utils-3.7.6-18.el9_1.aarch64.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.aarch64.rpm ppc64le: gnutls-c++-3.7.6-18.el9_1.ppc64le.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-dane-3.7.6-18.el9_1.ppc64le.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-debugsource-3.7.6-18.el9_1.ppc64le.rpm gnutls-devel-3.7.6-18.el9_1.ppc64le.rpm gnutls-utils-3.7.6-18.el9_1.ppc64le.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.ppc64le.rpm s390x: gnutls-c++-3.7.6-18.el9_1.s390x.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-dane-3.7.6-18.el9_1.s390x.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-debugsource-3.7.6-18.el9_1.s390x.rpm gnutls-devel-3.7.6-18.el9_1.s390x.rpm gnutls-utils-3.7.6-18.el9_1.s390x.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.s390x.rpm x86_64: gnutls-c++-3.7.6-18.el9_1.i686.rpm gnutls-c++-3.7.6-18.el9_1.x86_64.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-dane-3.7.6-18.el9_1.i686.rpm gnutls-dane-3.7.6-18.el9_1.x86_64.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-debugsource-3.7.6-18.el9_1.i686.rpm gnutls-debugsource-3.7.6-18.el9_1.x86_64.rpm gnutls-devel-3.7.6-18.el9_1.i686.rpm gnutls-devel-3.7.6-18.el9_1.x86_64.rpm gnutls-utils-3.7.6-18.el9_1.x86_64.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.x86_64.rpm Red Hat Enterprise Linux BaseOS (v.9): Source: gnutls-3.7.6-18.el9_1.src.rpm aarch64: gnutls-3.7.6-18.el9_1.aarch64.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-debugsource-3.7.6-18.el9_1.aarch64.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.aarch64.rpm ppc64le: gnutls-3.7.6-18.el9_1.ppc64le.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-debugsource-3.7.6-18.el9_1.ppc64le.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.ppc64le.rpm s390x: gnutls-3.7.6-18.el9_1.s390x.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-debugsource-3.7.6-18.el9_1.s390x.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.s390x.rpm x86_64: gnutls-3.7.6-18.el9_1.i686.rpm gnutls-3.7.6-18.el9_1.x86_64.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-debugsource-3.7.6-18.el9_1.i686.rpm gnutls-debugsource-3.7.6-18.el9_1.x86_64.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZAiXKtzjgjWX9erEAQj1PhAAm9pbTVkxqdaH6LY4JzDurjlXVLuvsCBE RetJQTum/aKtOCXwIFWesFH7Rsg4rXYXFtEw+aNElduH9lkD4O8TMh25NW4E3eHa /laWHNySOuAA+CsUR4vEs1pm/UKZ1hAPKlLn/RGDugy2nhcqPo84Th8e72rura3q PBzuo+7bmrp3Mu0XNFPbi8prayBH5VAer+Pg4F8rke2T++I2u2vMgNx0u28TmxQo qMyfsYR86VGYoc1GY1lR6wlrs96ZwNgsaySABoFK8yv4kSuuX1XArwEsdmJ7eXIt ZCo/Wgr7oqB2vpKx/bRrCrk6sZMQCQZpYnT+I4wlfAk/RNyBzo+ppUlTrWElbQjg OoullWaH0qt4BQJdPwznekWaUOV0yOlerW0en33ICiMQ+nseCEBSOuH8y24iI/XB ikp7Ivulwqe+z4oeJREKtbY2/cOKwbLhP6ZvKKzuFjwDLkPXF2cudSHKGJZPnZVw KSj7Y0U5EbcXcN422BRN03lw6dihC2efNxFy8W56KPEhZi6mmeCAwWtFP0iNFqnf ZtrgTW6fbSn5r7hjQe8oU+R5O1ylojoxhSrgOVmjLpXZEkbKCO9zLga+nL0L4KIW M87LjOeJ1aXu2IjHISxNRNTcqWrUPLVevk09KVqbNe47vl2B+g7qJxVKY2k20i/4 YFb0PskSBR0=ER5a -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.