CVE-2024-0553: Gnutls: incomplete fix for cve-2023-5981
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
Other sources
GnuTLS could allow a remote attacker to obtain sensitive information. By perform a timing side-channel attack in the RSA-PSK key exchange, a remote attacker could exploit this vulnerability to obtain sensitive information.
— IBM
Gnutls: incomplete fix for cve-2023-5981
— Microsoft
While the fix released for CVE-2023-5981 improves the side-channel situation, it does not eliminate the side-channel leakage in RSA-PSK ciphersuites.
https://gitlab.com/gnutls/gnutls/-/issues/1522
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gnutlsto a version that resolves this vulnerability.Fixed in 3.8.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20.1.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.1.317.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.8.4 - Upgrade
Upgrade
debian/gnutls28to a version that resolves this vulnerability.Fixed in 3.7.1-5+deb11u5Fixed in 3.7.1-5+deb11u10Fixed in 3.7.9-2+deb12u6Fixed in 3.7.9-2+deb12u7Fixed in 3.8.9-3+deb13u3Fixed in 3.8.9-3+deb13u4Fixed in 3.8.13-1 - Upgrade
Upgrade
GnuTLS (gnutls)to a version that resolves this vulnerability.Fixed in 3.8.3 - Compensating control
If RSA-PSK ciphersuites are in use, reduce exposure to the timing side-channel by disabling RSA-PSK ciphersuites until the GnuTLS update (3.8.3) is applied, since the incomplete fix for CVE-2023-5981 does not eliminate the side-channel leakage in RSA-PSK ciphersuites.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0553?
CVE-2024-0553 is classified as a medium severity vulnerability due to its potential for enabling timing side-channel attacks.
How do I fix CVE-2024-0553?
To remediate CVE-2024-0553, upgrade to the patched versions of GnuTLS which include 3.6.7-4+deb10u12, 3.7.9-2+deb12u2, or 3.8.5-2.
Which software versions are affected by CVE-2024-0553?
CVE-2024-0553 affects multiple versions of GnuTLS, including 3.6.x, 3.7.x, and 3.8.x prior to the patches specified.
Who can exploit CVE-2024-0553?
A remote attacker can exploit CVE-2024-0553 by sending malformed ciphertexts to perform timing side-channel attacks.
What software packages are impacted by CVE-2024-0553?
CVE-2024-0553 impacts software packages such as gnutls28 on Debian and Ubuntu, as well as several F5 BIG-IP applications.