Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":14.29,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":4,"type":"x","order":2,"pct":57.14,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":28.57,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 7 articles for you...
100

SUSE: 2025:1550-1 important: openssl-3 timing issue patch

* bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607 . # Security update for openssl-3 Announcement ID: SUSE-SU-2025:1550-1 Release Date: 2025-05-14T17:05:27Z Rating: important References: * bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607 Cross-References: * CVE-2025-27587 CVSS scores: * CVE-2025-27587 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-27587 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has four security fixes can now be installed. ## Description: This update for openssl-3 fixes the following issues: Security: * CVE-2025-27587: Timing side channel vulnerability in the P-384 implementation when used with ECDSA in the PPC architecture (bsc#1240366). * Missing null pointer check before accessing handshake_func in ssl_lib.c (bsc#1240607). FIPS: * Disabling EMS in OpenSSL configuration prevents sshd from starting (bsc#1230959, bsc#1232326, bsc#1231748). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1550=1 openSUSE-SLE-15.6-2025-1550=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1550=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libopenssl3-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.27.1 * openssl-3-3.1.4-150600.5.27.1 * openssl-3-debuginfo-3.1.4-150600.5.27.1 *libopenssl-3-devel-3.1.4-150600.5.27.1 * openssl-3-debugsource-3.1.4-150600.5.27.1 * libopenssl3-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-3.1.4-150600.5.27.1 * openSUSE Leap 15.6 (x86_64) * libopenssl3-32bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-devel-32bit-3.1.4-150600.5.27.1 * libopenssl3-32bit-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.27.1 * openSUSE Leap 15.6 (noarch) * openssl-3-doc-3.1.4-150600.5.27.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl3-64bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-devel-64bit-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-64bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-64bit-3.1.4-150600.5.27.1 * libopenssl3-64bit-3.1.4-150600.5.27.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libopenssl3-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.27.1 * openssl-3-3.1.4-150600.5.27.1 * openssl-3-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-devel-3.1.4-150600.5.27.1 * openssl-3-debugsource-3.1.4-150600.5.27.1 * libopenssl3-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-3.1.4-150600.5.27.1 * Basesystem Module 15-SP6 (x86_64) * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.27.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.27.1 * libopenssl3-32bit-3.1.4-150600.5.27.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27587.html * https://bugzilla.suse.com/show_bug.cgi?id=1230959 * https://bugzilla.suse.com/show_bug.cgi?id=1231748 * https://bugzilla.suse.com/show_bug.cgi?id=1232326 * https://bugzilla.suse.com/show_bug.cgi?id=1240366 * https://bugzilla.suse.com/show_bug.cgi?id=1240607 . The recent OpenSSL-3 release for SUSE resolves a significant timing vulnerability and rectifies issuesassociated with sshd errors.. openssl update, SUSE security patch, important security advisory, timing issue fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 14, 2025 Important SuSE
202

openSUSE 15.6 SUSE-SU-2025:0613-1 moderate: OpenSSL-1_1 Timing Issue

An update that solves one vulnerability and has one security fix can now be installed.. # Security update for openssl-1_1 Announcement ID: SUSE-SU-2025:0613-1 Release Date: 2025-02-21T10:38:08Z Rating: moderate References: * bsc#1236136 * bsc#1236771 Cross-References: * CVE-2024-13176 CVSS scores: * CVE-2024-13176 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-13176 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-13176 ( NVD ): 4.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L Affected Products: * Basesystem Module 15-SP6 * Development Tools Module 15-SP6 * Legacy Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for openssl-1_1 fixes the following issues: * CVE-2024-13176: Fixed timing side-channel in the ECDSA signature computation (bsc#1236136). Other bugfixes: * Non approved PBKDF parameters wrongly resulting as approved (bsc#1236771). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-613=1 openSUSE-SLE-15.6-2025-613=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-613=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-613=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-613=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libopenssl1_1-1.1.1w-150600.5.12.2 *libopenssl1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-1.1.1w-150600.5.12.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-debugsource-1.1.1w-150600.5.12.2 * libopenssl-1_1-devel-1.1.1w-150600.5.12.2 * openSUSE Leap 15.6 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1w-150600.5.12.2 * libopenssl1_1-32bit-1.1.1w-150600.5.12.2 * libopenssl-1_1-devel-32bit-1.1.1w-150600.5.12.2 * openSUSE Leap 15.6 (noarch) * openssl-1_1-doc-1.1.1w-150600.5.12.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl1_1-64bit-debuginfo-1.1.1w-150600.5.12.2 * libopenssl1_1-64bit-1.1.1w-150600.5.12.2 * libopenssl-1_1-devel-64bit-1.1.1w-150600.5.12.2 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libopenssl1_1-debuginfo-1.1.1w-150600.5.12.2 * libopenssl1_1-1.1.1w-150600.5.12.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-debugsource-1.1.1w-150600.5.12.2 * Basesystem Module 15-SP6 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1w-150600.5.12.2 * libopenssl1_1-32bit-1.1.1w-150600.5.12.2 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * openssl-1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-debugsource-1.1.1w-150600.5.12.2 * libopenssl-1_1-devel-1.1.1w-150600.5.12.2 * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1w-150600.5.12.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.12.2 * openssl-1_1-1.1.1w-150600.5.12.2 ## References: * https://www.suse.com/security/cve/CVE-2024-13176.html * https://bugzilla.suse.com/show_bug.cgi?id=1236136 * https://bugzilla.suse.com/show_bug.cgi?id=1236771 . OpenSSL-1_1 security enhancement on 2025-02-21 resolves timing vulnerabilities and contains an update for SUSE.. OpenSSL Update, SUSE Security Advisory, Timing Side-Channel, Open Source Security, Package Update. . LinuxSecurity.com Team

Calendar%202 Feb 21, 2025 OpenSUSE
100

SUSE Linux Enterprise: 2023:4983-1 Moderate: gnutls Timing Issue

* bsc#1217277 Cross-References: * CVE-2023-5981 . # Security update for gnutls Announcement ID: SUSE-SU-2023:4983-1 Rating: moderate References: * bsc#1217277 Cross-References: * CVE-2023-5981 CVSS scores: * CVE-2023-5981 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-5981 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for gnutls fixes the following issues: * CVE-2023-5981: Fixed timing side-channel inside RSA-PSK key exchange (bsc#1217277). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4983=1 SUSE-2023-4983=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-4983=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4983=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patchSUSE-SLE-Micro-5.4-2023-4983=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4983=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2023-4983=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4983=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4983=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libgnutlsxx-devel-3.7.3-150400.4.38.1 * libgnutlsxx28-3.7.3-150400.4.38.1 * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-guile-debuginfo-3.7.3-150400.4.38.1 * gnutls-guile-3.7.3-150400.4.38.1 * libgnutls-devel-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * openSUSE Leap 15.4 (x86_64) * libgnutls-devel-32bit-3.7.3-150400.4.38.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-32bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.38.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgnutls30-64bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-64bit-3.7.3-150400.4.38.1 * libgnutls-devel-64bit-3.7.3-150400.4.38.1 * libgnutls30-64bit-debuginfo-3.7.3-150400.4.38.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libgnutlsxx-devel-3.7.3-150400.4.38.1 * libgnutlsxx28-3.7.3-150400.4.38.1 * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 *libgnutlsxx28-debuginfo-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-guile-debuginfo-3.7.3-150400.4.38.1 * gnutls-guile-3.7.3-150400.4.38.1 * libgnutls-devel-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * openSUSE Leap 15.5 (x86_64) * libgnutls-devel-32bit-3.7.3-150400.4.38.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-32bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.38.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libgnutlsxx-devel-3.7.3-150400.4.38.1 * libgnutlsxx28-3.7.3-150400.4.38.1 * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * libgnutls-devel-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * Basesystem Module 15-SP4 (x86_64) *libgnutls30-32bit-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-32bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.38.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libgnutlsxx-devel-3.7.3-150400.4.38.1 * libgnutlsxx28-3.7.3-150400.4.38.1 * gnutls-debugsource-3.7.3-150400.4.38.1 * libgnutls30-hmac-3.7.3-150400.4.38.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.38.1 * gnutls-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-3.7.3-150400.4.38.1 * libgnutls-devel-3.7.3-150400.4.38.1 * gnutls-3.7.3-150400.4.38.1 * libgnutls30-debuginfo-3.7.3-150400.4.38.1 * Basesystem Module 15-SP5 (x86_64) * libgnutls30-32bit-debuginfo-3.7.3-150400.4.38.1 * libgnutls30-32bit-3.7.3-150400.4.38.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.38.1 ## References: * https://www.suse.com/security/cve/CVE-2023-5981.html * https://bugzilla.suse.com/show_bug.cgi?id=1217277 . SUSE announced a security update for gnutls addressing a timing side-channel flaw assessed with moderate risk.. Gnutls Update, Timing Side-Channel, Linux Security Update. . LinuxSecurity.com Team

Calendar%202 Dec 28, 2023 SuSE
100

SUSE: 2023:2160-2 Moderate: OpenSSL Timing Vulnerability in SUSE/SLE15

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2160-1 Container Tags : bci/bci-base:15.4 , bci/bci-base:15.4.27.14.72 , suse/sle15:15.4 , suse/sle15:15.4.27.14.72 Container Release : 27.14.72 Severity : moderate Type : security References : 1201627 1207534 CVE-2022-4304 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2648-1 Released: Tue Jun 27 09:52:35 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1201627,1207534,CVE-2022-4304 This update for openssl-1_1 fixes the following issues: - CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption. The previous fix for this timing side channel turned out to cause a severe 2-3x performance regression in the typical use case (bsc#1207534). - Update further expiring certificates that affect the testsuite (bsc#1201627). The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150400.7.42.1 updated - libopenssl1_1-1.1.1l-150400.7.42.1 updated - openssl-1_1-1.1.1l-150400.7.42.1 updated . Routine security enhancement for suse/sle15 container features updates addressing openssl vulnerabilities and optimizations for better performance.. SUSE Container Update, Openssl Patch, Security Advisory. . LinuxSecurity.com Team

Calendar%202 Jun 28, 2023 SuSE
89

Fedora 36 Advisory: Gnutls 3.8.0 Critical Update For Timing Issue

Release of gnutls 3.8.0 (fixes CVE-2023-0361) Release of gnutls guile bingings as standalone package.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-4fc4c33f2b 2023-03-18 05:00:58.357244 --------------------------------------------------------------------------------Name : guile-gnutls Product : Fedora 36 Version : 3.7.11 Release : 1.fc36 URL : https://gitlab.com/gnutls/guile Summary : Guile bindings for the GNUTLS library Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. This package contains Guile bindings for the library. --------------------------------------------------------------------------------Update Information: Release of gnutls 3.8.0 (fixes CVE-2023-0361) Release of gnutls guile bingings as standalone package. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 22 2023 Zoltan Fridrich - 3.7.11-1 - Initial import (fedora#2172108). --------------------------------------------------------------------------------References: [ 1 ] Bug #2168848 - gnutls-3.7.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2168848 [ 2 ] Bug #2169608 - CVE-2023-0361 gnutls: timing side-channel in the TLS RSA key exchange code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2169608 [ 3 ] Bug #2173612 - Error while performing self checks in FIPS mode https://bugzilla.redhat.com/show_bug.cgi?id=2173612 [ 4 ] Bug #2174758 - GNUTLS 3.8.0 changed ABI on i686 breaking all APIs using time_t https://bugzilla.redhat.com/show_bug.cgi?id=2174758 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-4fc4c33f2b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . GnuTLS version 3.8.0 rolled out, addressing CVE-2023-0361 vulnerabilities in Fedora 36. Make sure to upgrade to the latest standalone Guile bindings now!. Fedora Gnutls Update, CVE-2023-0361 Fix, Guile Bindings Release. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 18, 2023 Critical Fedora
89

Fedora 38: FEDORA-2023-5b378b82b3 Moderate: GnuTLS Timing Issue

Release of gnutls 3.8.0 (fixes CVE-2023-0361) Release of gnutls guile bingings as standalone package.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-5b378b82b3 2023-03-14 00:16:44.046934 --------------------------------------------------------------------------------Name : guile-gnutls Product : Fedora 38 Version : 3.7.11 Release : 1.fc38 URL : https://gitlab.com/gnutls/guile Summary : Guile bindings for the GNUTLS library Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. This package contains Guile bindings for the library. --------------------------------------------------------------------------------Update Information: Release of gnutls 3.8.0 (fixes CVE-2023-0361) Release of gnutls guile bingings as standalone package. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 22 2023 Zoltan Fridrich - 3.7.11-1 - Initial import (fedora#2172108). --------------------------------------------------------------------------------References: [ 1 ] Bug #2168848 - gnutls-3.7.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2168848 [ 2 ] Bug #2169608 - CVE-2023-0361 gnutls: timing side-channel in the TLS RSA key exchange code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2169608 [ 3 ] Bug #2173612 - Error while performing self checks in FIPS mode https://bugzilla.redhat.com/show_bug.cgi?id=2173612 [ 4 ] Bug #2174758 - GNUTLS 3.8.0 changed ABI on i686 breaking all APIs using time_t https://bugzilla.redhat.com/show_bug.cgi?id=2174758 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-5b378b82b3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The upgrade to GnuTLS 3.8.0 in Fedora 38 addresses a critical timing side-channel vulnerability, while also providing Guile bindings as a separate installable package.. Fedora 38, GnuTLS, Security Patch, Guile, Timing Issue. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Mar 14, 2023 Medium Fedora
219

Rocky Linux 9 RLSA-2023:1141 Moderate: GnuTLS Security Fix Overview

Moderate: gnutls security and bug fix update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1141", "synopsis": "Moderate: gnutls security and bug fix update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for gnutls.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.\n\nSecurity Fix(es):\n\n* gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* CCM tag length should be limited to known values (BZ#2144535)\n\n* In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator (BZ#2144537)\n\n* dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode (BZ#2149640)", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2144537", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2144537", "description": "* In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator"}, {"ticket": "2149640", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2149640", "description": "* dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode"}, {"ticket": "2162596", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162596", "description": ""}], "cves": [{"name": "CVE-2023-0361", "sourceBy": "MITRE","sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-0361", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-03-08T16:38:32.734709Z", "rpms": {"Rocky Linux 9": {"nvras": ["gnutls-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-0:3.7.6-18.el9_1.src.rpm", "gnutls-c++-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-c++-debuginfo-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-dane-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-dane-debuginfo-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-debuginfo-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-debugsource-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-devel-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-utils-0:3.7.6-18.el9_1.aarch64.rpm", "gnutls-utils-debuginfo-0:3.7.6-18.el9_1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux introduces a substantial OpenSSL maintenance and feature enhancement update, addressing critical vulnerabilities and reinforcing system security aspects.. Rocky Linux Security Update,GnuTLS Bug Fix, Linux Security Advisory,Gnutls Cryptography Patch. . LinuxSecurity.com Team

Calendar%202 Mar 08, 2023 Rocky Linux
98

Red Hat 9 RHSA-2023:1141 Moderate: Timing Side-Channel in GnuTLS

An update for gnutls is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: gnutls security and bug fix update Advisory ID: RHSA-2023:1141-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1141 Issue date: 2023-03-07 CVE Names: CVE-2023-0361 ==================================================================== 1. Summary: An update for gnutls is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): * gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * CCM tag length should be limited to known values (BZ#2144535) * In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide anindicator (BZ#2144537) * dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode (BZ#2149640) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2144537 - In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator [rhel-9.1.0.z] 2149640 - dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode [rhel-9.1.0.z] 2162596 - CVE-2023-0361 gnutls: timing side-channel in the TLS RSA key exchange code 6. Package List: Red Hat Enterprise Linux AppStream (v.9): aarch64: gnutls-c++-3.7.6-18.el9_1.aarch64.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-dane-3.7.6-18.el9_1.aarch64.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-debugsource-3.7.6-18.el9_1.aarch64.rpm gnutls-devel-3.7.6-18.el9_1.aarch64.rpm gnutls-utils-3.7.6-18.el9_1.aarch64.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.aarch64.rpm ppc64le: gnutls-c++-3.7.6-18.el9_1.ppc64le.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-dane-3.7.6-18.el9_1.ppc64le.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-debugsource-3.7.6-18.el9_1.ppc64le.rpm gnutls-devel-3.7.6-18.el9_1.ppc64le.rpm gnutls-utils-3.7.6-18.el9_1.ppc64le.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.ppc64le.rpm s390x: gnutls-c++-3.7.6-18.el9_1.s390x.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-dane-3.7.6-18.el9_1.s390x.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-debugsource-3.7.6-18.el9_1.s390x.rpm gnutls-devel-3.7.6-18.el9_1.s390x.rpm gnutls-utils-3.7.6-18.el9_1.s390x.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.s390x.rpm x86_64: gnutls-c++-3.7.6-18.el9_1.i686.rpm gnutls-c++-3.7.6-18.el9_1.x86_64.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-dane-3.7.6-18.el9_1.i686.rpm gnutls-dane-3.7.6-18.el9_1.x86_64.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-debugsource-3.7.6-18.el9_1.i686.rpm gnutls-debugsource-3.7.6-18.el9_1.x86_64.rpm gnutls-devel-3.7.6-18.el9_1.i686.rpm gnutls-devel-3.7.6-18.el9_1.x86_64.rpm gnutls-utils-3.7.6-18.el9_1.x86_64.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.x86_64.rpm Red Hat Enterprise Linux BaseOS (v.9): Source: gnutls-3.7.6-18.el9_1.src.rpm aarch64: gnutls-3.7.6-18.el9_1.aarch64.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-debuginfo-3.7.6-18.el9_1.aarch64.rpm gnutls-debugsource-3.7.6-18.el9_1.aarch64.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.aarch64.rpm ppc64le: gnutls-3.7.6-18.el9_1.ppc64le.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-debuginfo-3.7.6-18.el9_1.ppc64le.rpm gnutls-debugsource-3.7.6-18.el9_1.ppc64le.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.ppc64le.rpm s390x: gnutls-3.7.6-18.el9_1.s390x.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-debuginfo-3.7.6-18.el9_1.s390x.rpm gnutls-debugsource-3.7.6-18.el9_1.s390x.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.s390x.rpm x86_64: gnutls-3.7.6-18.el9_1.i686.rpm gnutls-3.7.6-18.el9_1.x86_64.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-c++-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-dane-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-debuginfo-3.7.6-18.el9_1.x86_64.rpm gnutls-debugsource-3.7.6-18.el9_1.i686.rpm gnutls-debugsource-3.7.6-18.el9_1.x86_64.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.i686.rpm gnutls-utils-debuginfo-3.7.6-18.el9_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZAiXKtzjgjWX9erEAQj1PhAAm9pbTVkxqdaH6LY4JzDurjlXVLuvsCBE RetJQTum/aKtOCXwIFWesFH7Rsg4rXYXFtEw+aNElduH9lkD4O8TMh25NW4E3eHa /laWHNySOuAA+CsUR4vEs1pm/UKZ1hAPKlLn/RGDugy2nhcqPo84Th8e72rura3q PBzuo+7bmrp3Mu0XNFPbi8prayBH5VAer+Pg4F8rke2T++I2u2vMgNx0u28TmxQo qMyfsYR86VGYoc1GY1lR6wlrs96ZwNgsaySABoFK8yv4kSuuX1XArwEsdmJ7eXIt ZCo/Wgr7oqB2vpKx/bRrCrk6sZMQCQZpYnT+I4wlfAk/RNyBzo+ppUlTrWElbQjg OoullWaH0qt4BQJdPwznekWaUOV0yOlerW0en33ICiMQ+nseCEBSOuH8y24iI/XB ikp7Ivulwqe+z4oeJREKtbY2/cOKwbLhP6ZvKKzuFjwDLkPXF2cudSHKGJZPnZVw KSj7Y0U5EbcXcN422BRN03lw6dihC2efNxFy8W56KPEhZi6mmeCAwWtFP0iNFqnf ZtrgTW6fbSn5r7hjQe8oU+R5O1ylojoxhSrgOVmjLpXZEkbKCO9zLga+nL0L4KIW M87LjOeJ1aXu2IjHISxNRNTcqWrUPLVevk09KVqbNe47vl2B+g7qJxVKY2k20i/4 YFb0PskSBR0=ER5a -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . RedHat issued a crucial advisory about a gnutls update that resolves a moderate security flaw and includes essential bug fixes for better stability and performance.. Red Hat Enterprise Linux, GnuTLS Update, TLS Issue. . LinuxSecurity.com Team

Calendar%202 Mar 08, 2023 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":14.29,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":4,"type":"x","order":2,"pct":57.14,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":28.57,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200