RHSA-2024:1879: Moderate: gnutls security update
Moderate: gnutls security update
Other sources
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.Security Fix(es): gnutls: vulnerable to Minerva side-channel information leak (CVE-2024-28834) gnutls: potential crash during chain building/verification (CVE-2024-28835) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1879?
The severity of RHSA-2024:1879 is categorized as moderate.
How do I fix RHSA-2024:1879?
To fix RHSA-2024:1879, update the gnutls package to version 3.7.6-23.el9_3.4 or later.
What systems are affected by RHSA-2024:1879?
RHSA-2024:1879 affects multiple versions of the gnutls and gnutls-dane packages on Red Hat Enterprise Linux.
What kind of vulnerability is addressed in RHSA-2024:1879?
RHSA-2024:1879 addresses a vulnerability related to a Minerva side-channel information leak in gnutls.
Is there a workaround for RHSA-2024:1879?
There are no specific workarounds mentioned for RHSA-2024:1879, so applying the update is recommended.