Lucene search

K
oraclelinuxOracleLinuxELSA-2024-12336
HistoryApr 19, 2024 - 12:00 a.m.

gnutls security update

2024-04-1900:00:00
linux.oracle.com
18
gnutls
security update
fips package
vulnerabilities
loop detection
side-channel attacks

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

62.0%

[3.7.6-23.4_fips]

  • Add FIPS package change: add fips suffix to Release and
    set Epoch to 10 [Orabug: 35925409]
  • Update FIPS module name for Oracle Linux [Orabug: 35925409]
  • Verify salt length and iteration count for PBKDF [Orabug: 35925409]
    [3.7.6-23.4]
  • Fix timing side-channel in deterministic ECDSA (RHEL-28958)
  • Fix potential crash during chain building/verification (RHEL-28953)
    [3.7.6-23.3]
  • x509: detect loop in certificate chain (RHEL-21759)
  • fips: Zeroize temporary values in integrity check (RHEL-21870)
    [3.7.6-23.2]
  • auth/rsa_psk: minimize branching after decryption
    [3.7.6-23.1]
  • auth/rsa_psk: side-step potential side-channel (RHEL-16755)
    [3.7.6-23]
  • Mark SHA-1 signature verification non-approved in FIPS (#2102751)
    [3.7.6-22]
  • Skip KTLS test on old kernel if host and target arches are different

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

62.0%