RHSA-2024:1784: Moderate: gnutls security update
Moderate: gnutls security update
Other sources
The gnutls package provide the GNU Transport Layer Security (GnuTLS) library,which implements cryptographic algorithms and protocols such as SSL, TLS, andDTLS.This package update fixes a timing side-channel in deterministic ECDSA.Security Fix(es): gnutls: vulnerable to Minerva side-channel information leak (CVE-2024-28834) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1784?
The severity of RHSA-2024:1784 is classified as moderate.
How do I fix RHSA-2024:1784?
To fix RHSA-2024:1784, update the gnutls package to version 3.6.16-8.el8_9.3 or later.
Which software is affected by RHSA-2024:1784?
The software affected by RHSA-2024:1784 includes various versions of Red Hat Enterprise Linux and the gnutls package.
What issue does RHSA-2024:1784 address?
RHSA-2024:1784 addresses a timing side-channel vulnerability in deterministic ECDSA.
When was RHSA-2024:1784 released?
RHSA-2024:1784 was released to address security updates related to gnutls.