Summary: | <dev-libs/openssl-{3.1.8, 3.2.4, 3.3.3}: Timing side-channel in ECDSA signature computation | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Christopher Fore <csfore> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | normal | CC: | base-system |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://openssl-library.org/news/secadv/20250120.txt | ||
Whiteboard: | A4 [glsa? cleanup] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 949643, 949644, 949645 | ||
Bug Blocks: |
Description
Christopher Fore
2025-01-21 21:42:45 UTC
Releases are out now. I've started bumping these but may not finish until later. commit ca397f75d7bb3124b8cc8faff1c27790c2b55764 Author: Patrick McLean <chutzpah@gentoo.org> Date: Tue Feb 11 08:10:56 2025 -0800 dev-libs/openssl: add 3.3.3 Signed-off-by: Patrick McLean <chutzpah@gentoo.org> commit 26b201c972381ff1325091061a4ad899c74a918d Author: Patrick McLean <chutzpah@gentoo.org> Date: Tue Feb 11 08:45:58 2025 -0800 dev-libs/openssl: add 3.2.4 Signed-off-by: Patrick McLean <chutzpah@gentoo.org> commit ed25cc8ff17852978ca5c15741cf9ee72d0ecbed Author: Patrick McLean <chutzpah@gentoo.org> Date: Tue Feb 11 09:02:02 2025 -0800 dev-libs/openssl: add 3.1.8 Signed-off-by: Patrick McLean <chutzpah@gentoo.org> commit ed25cc8ff17852978ca5c15741cf9ee72d0ecbed Author: Patrick McLean <chutzpah@gentoo.org> Date: Tue Feb 11 09:02:02 2025 -0800 dev-libs/openssl: add 3.1.8 Signed-off-by: Patrick McLean <chutzpah@gentoo.org> |