|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-23170: mbedtls: timing side channel in private key RSA operations | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Distribution | Reporter: | SMASH SMASH <smash_bz> |
| Component: | Other | Assignee: | Martin Pluskal <mpluskal> |
| Status: | IN_PROGRESS --- | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | andrea.mattiazzo, jaime.marquinez.ferrandiz, meissner |
| Version: | Leap 15.6 | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/392471/ | ||
| Whiteboard: | |||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
SMASH SMASH
2024-01-30 08:57:39 UTC
Tracking as affected: - openSUSE:Backports:SLE-15-SP4/mbedtls 2.28.0 - openSUSE:Backports:SLE-15-SP5/mbedtls 2.28.2 - openSUSE:Factory/mbedtls 3.5.1 - openSUSE:Factory/mbedtls-2 2.28.6 (In reply to Andrea Mattiazzo from comment #1) > Tracking as affected: > - openSUSE:Backports:SLE-15-SP4/mbedtls 2.28.0 Is SP4 still supported? (In reply to Martin Pluskal from comment #2) > (In reply to Andrea Mattiazzo from comment #1) > > Tracking as affected: > > - openSUSE:Backports:SLE-15-SP4/mbedtls 2.28.0 > Is SP4 still supported? No, it's not supported, so it's up to maintainers if they want to fix also that code stream or not. This is an autogenerated message for OBS integration: This bug (1219336) was mentioned in https://build.opensuse.org/request/show/1142919 Factory / mbedtls https://build.opensuse.org/request/show/1142922 Factory / mbedtls-2 https://build.opensuse.org/request/show/1142926 Backports:SLE-15-SP5 / mbedtls openSUSE-SU-2024:0037-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1219336 CVE References: CVE-2024-23170 JIRA References: Sources used: openSUSE Backports SLE-15-SP5 (src): mbedtls-2.28.7-bp155.2.3.1 |