Amazon Linux 2023 Security Advisory: ALAS-2024-736
Advisory Release Date: 2024-10-10 03:02 Pacific
Advisory Updated Date: 2024-10-14 16:00 Pacific
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts. (CVE-2024-2236)
Affected Packages:
libgcrypt
Issue Correction:
Run dnf update libgcrypt --releasever 2023.6.20241010 to update your system.
aarch64:
libgcrypt-debuginfo-1.10.2-1.amzn2023.0.2.aarch64
libgcrypt-devel-debuginfo-1.10.2-1.amzn2023.0.2.aarch64
libgcrypt-debugsource-1.10.2-1.amzn2023.0.2.aarch64
libgcrypt-1.10.2-1.amzn2023.0.2.aarch64
libgcrypt-devel-1.10.2-1.amzn2023.0.2.aarch64
src:
libgcrypt-1.10.2-1.amzn2023.0.2.src
x86_64:
libgcrypt-devel-1.10.2-1.amzn2023.0.2.x86_64
libgcrypt-1.10.2-1.amzn2023.0.2.x86_64
libgcrypt-devel-debuginfo-1.10.2-1.amzn2023.0.2.x86_64
libgcrypt-debuginfo-1.10.2-1.amzn2023.0.2.x86_64
libgcrypt-debugsource-1.10.2-1.amzn2023.0.2.x86_64