ALAS2023-2024-736


Amazon Linux 2023 Security Advisory: ALAS2023-2024-736
Advisory Released Date: 2024-10-14
Advisory Updated Date: 2024-10-14
Severity: Medium

Issue Overview:

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts. (CVE-2024-2236)


Affected Packages:

libgcrypt


Issue Correction:
Run dnf update libgcrypt --releasever 2023.6.20241010 to update your system.

New Packages:
aarch64:
    libgcrypt-debuginfo-1.10.2-1.amzn2023.0.2.aarch64
    libgcrypt-devel-debuginfo-1.10.2-1.amzn2023.0.2.aarch64
    libgcrypt-debugsource-1.10.2-1.amzn2023.0.2.aarch64
    libgcrypt-1.10.2-1.amzn2023.0.2.aarch64
    libgcrypt-devel-1.10.2-1.amzn2023.0.2.aarch64

src:
    libgcrypt-1.10.2-1.amzn2023.0.2.src

x86_64:
    libgcrypt-devel-1.10.2-1.amzn2023.0.2.x86_64
    libgcrypt-1.10.2-1.amzn2023.0.2.x86_64
    libgcrypt-devel-debuginfo-1.10.2-1.amzn2023.0.2.x86_64
    libgcrypt-debuginfo-1.10.2-1.amzn2023.0.2.x86_64
    libgcrypt-debugsource-1.10.2-1.amzn2023.0.2.x86_64