REDHAT-BUG-2467686: Low severity GnuTLS libgnutls vulnerability
libgnutls: Fix timing side-channel in PKCS#7 padding removal The PKCS#7 padding check performed during decryption was not constant-time, potentially leaking information about the padding bytes through timing differences. Rewritten to remove padding in a branch-free manner.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2467686?
The severity of REDHAT-BUG-2467686 is classified as low.
What is the main issue addressed in REDHAT-BUG-2467686?
REDHAT-BUG-2467686 addresses a timing side-channel vulnerability in the PKCS#7 padding removal process within libgnutls.
How do I fix REDHAT-BUG-2467686?
To mitigate REDHAT-BUG-2467686, update to the latest version of libgnutls that includes the fix for this vulnerability.
What can be the impact of not fixing REDHAT-BUG-2467686?
The unresolved REDHAT-BUG-2467686 could potentially allow an attacker to exploit timing differences to infer information about the decrypted padding.
Is REDHAT-BUG-2467686 relevant to all users of libgnutls?
Yes, REDHAT-BUG-2467686 is relevant to all users of libgnutls who rely on PKCS#7 padding for decryption operations.