ALAS-2024-736


Amazon Linux 2023 Security Advisory: ALAS-2024-736
Advisory Release Date: 2024-10-10 03:02 Pacific
Advisory Updated Date: 2024-10-14 16:00 Pacific
Severity: Medium

Issue Overview:

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts. (CVE-2024-2236)


Affected Packages:

libgcrypt


Issue Correction:
Run dnf update libgcrypt --releasever 2023.6.20241010 to update your system.

New Packages:
aarch64:
    libgcrypt-debuginfo-1.10.2-1.amzn2023.0.2.aarch64
    libgcrypt-devel-debuginfo-1.10.2-1.amzn2023.0.2.aarch64
    libgcrypt-debugsource-1.10.2-1.amzn2023.0.2.aarch64
    libgcrypt-1.10.2-1.amzn2023.0.2.aarch64
    libgcrypt-devel-1.10.2-1.amzn2023.0.2.aarch64

src:
    libgcrypt-1.10.2-1.amzn2023.0.2.src

x86_64:
    libgcrypt-devel-1.10.2-1.amzn2023.0.2.x86_64
    libgcrypt-1.10.2-1.amzn2023.0.2.x86_64
    libgcrypt-devel-debuginfo-1.10.2-1.amzn2023.0.2.x86_64
    libgcrypt-debuginfo-1.10.2-1.amzn2023.0.2.x86_64
    libgcrypt-debugsource-1.10.2-1.amzn2023.0.2.x86_64