Quote from upstream's security advisory: It was found that GnuTLS 3.6.3 introduced a regression in the DTLS protocol implementation. This caused the DTLS client to not contribute any randomness to the DTLS negotiation breaking the security guarantees of the DTLS protocol. Recommendation: To address the issue found upgrade to GnuTLS 3.6.13 or later versions.
@maintainer(s), please create an appropriate ebuild.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d9197424c42d02f8d2b330ac3cc08bedd54a0235 commit d9197424c42d02f8d2b330ac3cc08bedd54a0235 Author: Lars Wendler <polynomial-c@gentoo.org> AuthorDate: 2020-03-31 11:28:55 +0000 Commit: Lars Wendler <polynomial-c@gentoo.org> CommitDate: 2020-03-31 11:28:55 +0000 net-libs/gnutls: Security bump to version 3.6.13 Bug: https://bugs.gentoo.org/715602 Package-Manager: Portage-2.3.96, Repoman-2.3.22 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org> net-libs/gnutls/Manifest | 1 + net-libs/gnutls/gnutls-3.6.13.ebuild | 132 +++++++++++++++++++++++++++++++++++ 2 files changed, 133 insertions(+)
@maintainer(s), this isn't a great vulnerability at all, so are we alright to stabilise now? Thanks for super quick bump and report by the way.
ia64 will pass. See https://archives.gentoo.org/gentoo-dev/message/edaadc85d7423810dd6ecfeda29cc85f
arm stable
x86 stable
arm64 stable
amd64 stable
ppc stable
ppc64 stable
sparc stable
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b3c033cf9fc2695e35c44f837a0fc0b477cf30cf commit b3c033cf9fc2695e35c44f837a0fc0b477cf30cf Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2020-04-02 21:54:33 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2020-04-02 21:54:43 +0000 net-libs/gnutls: security cleanup Bug: https://bugs.gentoo.org/715602 Package-Manager: Portage-2.3.96, Repoman-2.3.22 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> net-libs/gnutls/Manifest | 2 - net-libs/gnutls/gnutls-3.6.12.ebuild | 132 --------------------------------- net-libs/gnutls/gnutls-3.6.7-r1.ebuild | 129 -------------------------------- 3 files changed, 263 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=de14163ee0d91a87d8b097835f640a05d5d7d76c commit de14163ee0d91a87d8b097835f640a05d5d7d76c Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2020-04-02 21:53:04 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2020-04-02 21:54:42 +0000 net-libs/gnutls: mark ia64, hppa & s390 stable (bug #715602) Bug: https://bugs.gentoo.org/715602 Package-Manager: Portage-2.3.96, Repoman-2.3.22 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> net-libs/gnutls/gnutls-3.6.13.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
New GLSA request filed.
This issue was resolved and addressed in GLSA 202004-06 at https://security.gentoo.org/glsa/202004-06 by GLSA coordinator Thomas Deutschmann (whissi).
Upstream bug: https://gitlab.com/gnutls/gnutls/-/issues/960 Still awaiting CVE.
Tree is clean.