Amazon Linux 2023 Security Advisory: ALAS2023-2024-736
Advisory Released Date: 2024-10-14
Advisory Updated Date: 2024-10-14
Severity:
Medium
Issue Overview:
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts. (CVE-2024-2236)
Affected Packages:
libgcrypt
Issue Correction:
Run dnf update libgcrypt --releasever 2023.6.20241010 to update your system.
New Packages:
aarch64:
libgcrypt-debuginfo-1.10.2-1.amzn2023.0.2.aarch64
libgcrypt-devel-debuginfo-1.10.2-1.amzn2023.0.2.aarch64
libgcrypt-debugsource-1.10.2-1.amzn2023.0.2.aarch64
libgcrypt-1.10.2-1.amzn2023.0.2.aarch64
libgcrypt-devel-1.10.2-1.amzn2023.0.2.aarch64
src:
libgcrypt-1.10.2-1.amzn2023.0.2.src
x86_64:
libgcrypt-devel-1.10.2-1.amzn2023.0.2.x86_64
libgcrypt-1.10.2-1.amzn2023.0.2.x86_64
libgcrypt-devel-debuginfo-1.10.2-1.amzn2023.0.2.x86_64
libgcrypt-debuginfo-1.10.2-1.amzn2023.0.2.x86_64
libgcrypt-debugsource-1.10.2-1.amzn2023.0.2.x86_64