RHSA-2023:1569: Moderate: gnutls security and bug fix update
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.Security Fix(es): gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): trap invalid opcode ip:7feef81809fe sp:7fee997419c0 error:0 in libgnutls.so.30.28.2[7feef8040000+1dd000] (BZ#2131152)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1569?
The vulnerability RHSA-2023:1569 is of high severity due to the timing side-channel in the TLS RSA key exchange code.
How do I fix RHSA-2023:1569?
To fix RHSA-2023:1569, update the gnutls package to version 3.6.16-6.el8_7 or later.
Which packages are affected by RHSA-2023:1569?
Packages affected by RHSA-2023:1569 include gnutls, gnutls-dane, and their corresponding debuginfo packages.
What is CVE-2023-0361 in relation to RHSA-2023:1569?
CVE-2023-0361 is the specific identifier for the timing side-channel vulnerability addressed in RHSA-2023:1569.
Is there a workaround for RHSA-2023:1569?
There is no recommended workaround for RHSA-2023:1569; the best action is to apply the security update.