Bugzilla – Bug 1105460
VUL-0: CVE-2018-10846: gnutls: "Just in Time" PRIME + PROBE cache-based side channel attack can lead to plaintext recovery
Last modified: 2021-07-27 12:35:28 UTC
rh#1582574 A cache-based side channel in GnuTLS implementation that leads to plaintext recovery in cross-VM attack setting was found. The attack exploits a novel "Just in Time" PRIME + PROBE attack in combination with a new variant of the original Lucky 13 attack. References: https://bugzilla.redhat.com/show_bug.cgi?id=1582574 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-10846
External references: https://eprint.iacr.org/2018/747 Upstream fix: https://gitlab.com/gnutls/gnutls/merge_requests/657
SUSE-SU-2018:2825-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1047002,1105437,1105459,1105460 CVE References: CVE-2017-10790,CVE-2018-10844,CVE-2018-10845,CVE-2018-10846 Sources used: SUSE OpenStack Cloud 7 (src): gnutls-3.2.15-18.6.1 SUSE Linux Enterprise Server for SAP 12-SP2 (src): gnutls-3.2.15-18.6.1 SUSE Linux Enterprise Server for SAP 12-SP1 (src): gnutls-3.2.15-18.6.1 SUSE Linux Enterprise Server 12-SP2-LTSS (src): gnutls-3.2.15-18.6.1 SUSE Linux Enterprise Server 12-SP1-LTSS (src): gnutls-3.2.15-18.6.1 SUSE Linux Enterprise Server 12-LTSS (src): gnutls-3.2.15-18.6.1 SUSE Enterprise Storage 4 (src): gnutls-3.2.15-18.6.1
SUSE-SU-2018:2842-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1047002,1105437,1105459,1105460 CVE References: CVE-2017-10790,CVE-2018-10844,CVE-2018-10845,CVE-2018-10846 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP3 (src): gnutls-3.3.27-3.3.1 SUSE Linux Enterprise Server 12-SP3 (src): gnutls-3.3.27-3.3.1 SUSE Linux Enterprise Desktop 12-SP3 (src): gnutls-3.3.27-3.3.1
openSUSE-SU-2018:2854-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1047002,1105437,1105459,1105460 CVE References: CVE-2017-10790,CVE-2018-10844,CVE-2018-10845,CVE-2018-10846 Sources used: openSUSE Leap 42.3 (src): gnutls-3.3.27-2.3.1
SUSE-SU-2018:2930-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1047002,1105437,1105459,1105460 CVE References: CVE-2017-10790,CVE-2018-10844,CVE-2018-10845,CVE-2018-10846 Sources used: SUSE Linux Enterprise Module for Desktop Applications 15 (src): gnutls-3.6.2-6.3.1 SUSE Linux Enterprise Module for Basesystem 15 (src): gnutls-3.6.2-6.3.1
openSUSE-SU-2018:2958-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1047002,1105437,1105459,1105460 CVE References: CVE-2017-10790,CVE-2018-10844,CVE-2018-10845,CVE-2018-10846 Sources used: openSUSE Leap 15.0 (src): gnutls-3.6.2-lp150.4.3.1
SUSE-SU-2018:2825-2: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1047002,1105437,1105459,1105460 CVE References: CVE-2017-10790,CVE-2018-10844,CVE-2018-10845,CVE-2018-10846 Sources used: SUSE Linux Enterprise Server 12-SP2-BCL (src): gnutls-3.2.15-18.6.1
SUSE-SU-2019:14058-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1047002,1105460 CVE References: CVE-2017-10790,CVE-2018-10846 Sources used: SUSE Linux Enterprise High Availability Extension 11-SP4 (src): gnutls-2.4.1-24.39.76.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Done