The container suse/sles12sp5 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp5 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2108-1 Container Tags : suse/sles12sp5:6.5.481 , suse/sles12sp5:latest Container Release : 6.5.481 Severity : moderate Type : security References : 1207534 CVE-2022-4304 ----------------------------------------------------------------- The container suse/sles12sp5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2624-1 Released: Fri Jun 23 13:43:30 2023 Summary: Security update for openssl-1_0_0 Type: security Severity: moderate References: 1207534,CVE-2022-4304 This update for openssl-1_0_0 fixes the following issues: - CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption. The previous fix for this timing side channel turned out to cause a severe 2-3x performance regression in the typical use case (bsc#1207534). The following package changes have been done: - libopenssl1_0_0-1.0.2p-3.78.1 updated - openssl-1_0_0-1.0.2p-3.78.1 updated . SUSE container advisory releases updates for openssl-1_1_1 that tackle stability concerns and vulnerability risks with integrated fixes.. SUSE Container, OpenSSL Update, Security Patches. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0946 https://linux.oracle.com/errata/ELSA-2023-0946.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: openssl-3.0.1-47.0.1.el9_1.x86_64.rpm openssl-devel-3.0.1-47.0.1.el9_1.i686.rpm openssl-devel-3.0.1-47.0.1.el9_1.x86_64.rpm openssl-libs-3.0.1-47.0.1.el9_1.i686.rpm openssl-libs-3.0.1-47.0.1.el9_1.x86_64.rpm openssl-perl-3.0.1-47.0.1.el9_1.x86_64.rpm aarch64: openssl-3.0.1-47.0.1.el9_1.aarch64.rpm openssl-devel-3.0.1-47.0.1.el9_1.aarch64.rpm openssl-libs-3.0.1-47.0.1.el9_1.aarch64.rpm openssl-perl-3.0.1-47.0.1.el9_1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//openssl-3.0.1-47.0.1.el9_1.src.rpm Related CVEs: CVE-2022-4203 CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0216 CVE-2023-0217 CVE-2023-0286 CVE-2023-0401 Description of changes: [3.0.1-47.0.1] - Replace upstream references [Orabug: 34340177] [1:3.0.1-47] - Fixed X.509 Name Constraints Read Buffer Overflow Resolves: CVE-2022-4203 - Fixed Timing Oracle in RSA Decryption Resolves: CVE-2022-4304 - Fixed Double free after calling PEM_read_bio_ex Resolves: CVE-2022-4450 - Fixed Use-after-free following BIO_new_NDEF Resolves: CVE-2023-0215 - Fixed Invalid pointer dereference in d2i_PKCS7 functions Resolves: CVE-2023-0216 - Fixed NULL dereference validating DSA public key Resolves: CVE-2023-0217 - Fixed X.400 address type confusion in X.509 GeneralName Resolves: CVE-2023-0286 - Fixed NULL dereference during PKCS7 data verification Resolves: CVE-2023-0401 [1:3.0.1-46] - Refactor OpenSSL fips module MAC verification Resolves: rhbz#2158412 - Disallow SHAKE in RSA-OAEP decryption in FIPS mode Resolves: rhbz#2144010 [1:3.0.1-45] - Add support of X25519 and X448 "group" parameter in EVP_PKEY_CTX objects Resolves: rhbz#2149010 - Fix explicit indicator for PSS salt length in FIPS mode when used with negative magic values Resolves: rhbz#2144012 - Update change to default PSS salt length with patch state from upstream Related: rhbz#2144012 [1:3.0.1-44] - SHAKE-128/256 are not allowed with RSA in FIPS mode Resolves: rhbz#2144010 - Avoid memory leaks in TLS Resolves: rhbz#2144008 - FIPS RSA CRT tests must use correct parameters Resolves: rhbz#2144006 - FIPS-140-3 permits only SHA1, SHA256, and SHA512 for DRBG-HASH/DRBG-HMAC Resolves: rhbz#2144017 - Remove support for X9.31 signature padding in FIPS mode Resolves: rhbz#2144015 - Add explicit indicator for SP 800-108 KDFs with short key lengths Resolves: rhbz#2144019 - Add explicit indicator for HMAC with short key lengths Resolves: rhbz#2144000 - Set minimum password length for PBKDF2 in FIPS mode Resolves: rhbz#2144003 - Add explicit indicator for PSS salt length in FIPS mode Resolves: rhbz#2144012 - Clamp default PSS salt length to digest size for FIPS 186-4 compliance Related: rhbz#2144012 - Forbid short RSA keys for key encapsulation/decapsulation in FIPS mode Resolves: rhbz#2145170 _______________________________________________ El-errata mailing list
New openssl packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] openssl (SSA:2023-038-01) New openssl packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/openssl-1.1.1t-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: X.400 address type confusion in X.509 GeneralName. Timing Oracle in RSA Decryption. Use-after-free following BIO_new_NDEF. Double free after calling PEM_read_bio_ex. For more information, see: https://openssl-library.org/news/secadv/20230207.txt https://www.cve.org/CVERecord?id=CVE-2023-0286 https://www.cve.org/CVERecord?id=CVE-2022-4304 https://www.cve.org/CVERecord?id=CVE-2023-0215 https://www.cve.org/CVERecord?id=CVE-2022-4450 (* Security fix *) patches/packages/openssl-solibs-1.1.1t-i586-1_slack15.0.txz: Upgraded. +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated packages for Slackware 15.0: Updated packages for Slackware x86_64 15.0: Updated packages for Slackware -current: Updated packages for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 packages: 91957e9cb9b1aafd2c62ee542dcf0b46 openssl-1.1.1t-i586-1_slack15.0.txz f016aff5335e01db83aa82273c5162e0 openssl-solibs-1.1.1t-i586-1_slack15.0.txz Slackware x86_64 15.0 packages: 2c7c51349bf330c02664fc5471bb1f02 openssl-1.1.1t-x86_64-1_slack15.0.txz 0d2c9b98fa75eef4f69de0342b3b5521 openssl-solibs-1.1.1t-x86_64-1_slack15.0.txz Slackware -current packages: d4cd4df4dad5a7b46b0d83878a7e8420 a/openssl-solibs-1.1.1t-i586-1.txz 849b9ec3e851984ec952bb1587a1e849 n/openssl-1.1.1t-i586-1.txz Slackware x86_64 -current packages: 012ecd508d7e12f3b437d7d2aa1a9261 a/openssl-solibs-1.1.1t-x86_64-1.txz 0b5e3d4defe82eb8bec1a80180cbf0e5 n/openssl-1.1.1t-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg openssl-1.1.1t-i586-1_slack15.0.txz openssl-solibs-1.1.1t-i586-1_slack15.0.txz +-----+ . Recent updates to the OpenSSL packages in Slackware bolster system security by addressing several vulnerabilities and improving overall robustness.. OpenSSL Security Update, Slackware Fixes, Software Patch Instructions. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.