Описание
Feature update for libgcrypt, libgpg-error
This update for libgcrypt, libgpg-error fixes the following issues:
Update libgcrypt to 1.12.1 (jsc#PED-15059):
- New and extended interfaces:
- Allow access to the FIPS service indicator via the new GCRYCTL_FIPS_SERVICE_INDICATOR control code.
- Make SHA-1 non-FIPS internally for the 1.12 API
- Add Dilithium (ML-DSA) support
- Support optional random-override and support byte string data
- Bug fixes:
- Use secure MPI in _gcry_mpi_assign_limb_space.
- Use CSIDL_COMMON_APPDATA instead of /etc on Windows.
- Apply a Kyber patch from upstream.
- Fix an edge case in Jent initialization.
- mceliece6688128f: Fix stack overflow crash on win64/wine
- Performance:
- Many performance improvements, new AVX512 implementations for modern CPUs.
- Add RISC-V Zbb+Zbc implementation of CRC.
- Add RISC-V vector cryptography implementation of GHASH, AES, SHA256 and SHA512
- Add AVX2 and AVX512 code paths to improve CRC.
For a full changelog, see: https://dev.gnupg.org/source/libgcrypt/history/master/;libgcrypt-1.12.0
Update libgpg-error to 1.58:
- New src/gpg-error.c (main): New command "fconcat".
- Rename src/spawn-posix.c (struct gpgrt_spawn_actions): Rename the field to ENVP.
- argparse: Use SYSCONFDIR for /etc.
- Update translations for Portugese, German
- src/estream.c (parse_mode): Fix parsing of "share". Set sysopen flag.
- syscfg: Add 64-bit Android arch.
Список пакетов
openSUSE Leap 16.0
libgcrypt-devel-1.12.1-160000.1.1
libgcrypt-devel-x86-64-v3-1.12.1-160000.1.1
libgcrypt20-1.12.1-160000.1.1
libgcrypt20-x86-64-v3-1.12.1-160000.1.1
libgpg-error-devel-1.58-160000.1.1
libgpg-error0-1.58-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE CVE CVE-2024-2236 page
Описание
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.
Затронутые продукты
openSUSE Leap 16.0:libgcrypt-devel-1.12.1-160000.1.1
openSUSE Leap 16.0:libgcrypt-devel-x86-64-v3-1.12.1-160000.1.1
openSUSE Leap 16.0:libgcrypt20-1.12.1-160000.1.1
openSUSE Leap 16.0:libgcrypt20-x86-64-v3-1.12.1-160000.1.1
Ссылки
- CVE-2024-2236
- SUSE Bug 1221107