RHSA-2023:1141: Moderate: gnutls security and bug fix update
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.Security Fix(es): gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): CCM tag length should be limited to known values (BZ#2144535) In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator (BZ#2144537) dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode (BZ#2149640)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1141?
The severity of RHSA-2023:1141 is classified as moderate.
What is CVE-2023-0361 related to RHSA-2023:1141?
CVE-2023-0361 pertains to a timing side-channel vulnerability in the TLS RSA key exchange code.
How do I fix RHSA-2023:1141?
To fix RHSA-2023:1141, update the gnutls packages to version 3.7.6-18.el9_1 or later.
Which packages are affected by RHSA-2023:1141?
The affected packages include gnutls, gnutls-dane, gnutls-debuginfo, gnutls-devel, and related packages.
Is upgrading gnutls the only solution for RHSA-2023:1141?
Yes, upgrading gnutls to the recommended version is the primary solution to mitigate the vulnerability.