Advisories ยป MGASA-2024-0037

Updated mbedtls packages fix security vulnerabilities

Publication date: 14 Feb 2024
Modification date: 14 Feb 2024
Type: security
Affected Mageia releases : 9

Description

This update brings the mbedtls packages from 2.28.3 to the latest 2.28.7
release in the LTS branch, fixing a number of bugs as well the following
security vulnerabilities:
- Buffer overread in TLS stream cipher suites.
- Timing side channel in private key RSA operations.
- Buffer overflow in mbedtls_x509_set_extension.
See the linked release notes for details.
                

References

SRPMS

9/core