RHSA-2023:1200: Moderate: gnutls security and bug fix update
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.<br>Security Fix(es):<br><li> gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> CCM tag length should be limited to known values (BZ#2144536)</li> <li> In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator (BZ#2144538)</li> <li> dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode (BZ#2149641)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1200?
The severity of RHSA-2023:1200 is classified as important due to a timing side-channel vulnerability in the TLS RSA key exchange code.
How do I fix RHSA-2023:1200?
To fix RHSA-2023:1200, update the gnutls packages to version 3.7.6-18.el9_0.
What vulnerability does RHSA-2023:1200 address?
RHSA-2023:1200 addresses a timing side-channel vulnerability identified as CVE-2023-0361.
What packages are affected by RHSA-2023:1200?
RHSA-2023:1200 affects the gnutls, gnutls-dane, and related packages across various architectures.
Is RHSA-2023:1200 specific to a certain operating system?
Yes, RHSA-2023:1200 specifically pertains to Red Hat Enterprise Linux.