Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 658056 (CVE-2018-0495) - <dev-libs/libgcrypt-1.8.3: ECDSA cache sidechannel
Summary: <dev-libs/libgcrypt-1.8.3: ECDSA cache sidechannel
Status: RESOLVED FIXED
Alias: CVE-2018-0495
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://lists.gnupg.org/pipermail/gnu...
Whiteboard: A4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-06-13 17:12 UTC by Hanno Böck
Modified: 2018-12-01 01:00 UTC (History)
1 user (show)

See Also:
Package list:
dev-libs/libgcrypt-1.8.3
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Larry the Git Cow gentoo-dev 2018-06-13 18:54:15 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b8ca457d79d94cf2bccff3c4085452c6d1a356e5

commit b8ca457d79d94cf2bccff3c4085452c6d1a356e5
Author:     Kristian Fiskerstrand <k_f@gentoo.org>
AuthorDate: 2018-06-13 18:53:22 +0000
Commit:     Kristian Fiskerstrand <k_f@gentoo.org>
CommitDate: 2018-06-13 18:54:06 +0000

    dev-libs/libgcrypt: New upstream version 1.8.3
    
    Bug: https://bugs.gentoo.org/658056
    Package-Manager: Portage-2.3.24, Repoman-2.3.6

 dev-libs/libgcrypt/Manifest               |  1 +
 dev-libs/libgcrypt/libgcrypt-1.8.3.ebuild | 75 +++++++++++++++++++++++++++++++
 2 files changed, 76 insertions(+)
Comment 2 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-06-14 10:54:16 UTC
amd64 stable
Comment 3 Larry the Git Cow gentoo-dev 2018-06-15 09:58:03 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1f44663d9f4b1680633dd7c998399539e198a2f0

commit 1f44663d9f4b1680633dd7c998399539e198a2f0
Author:     Sergei Trofimovich <slyfox@gentoo.org>
AuthorDate: 2018-06-15 09:57:45 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-06-15 09:57:45 +0000

    dev-libs/libgcrypt: stable 1.8.3 for ia64, bug #658056
    
    Bug: https://bugs.gentoo.org/658056
    Package-Manager: Portage-2.3.40, Repoman-2.3.9
    RepoMan-Options: --include-arches="ia64"

 dev-libs/libgcrypt/libgcrypt-1.8.3.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 4 Larry the Git Cow gentoo-dev 2018-06-15 15:56:35 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=70f5f861c44f230b0fd488ce763a77ccec1774e6

commit 70f5f861c44f230b0fd488ce763a77ccec1774e6
Author:     Rolf Eike Beer <eike@sf-mail.de>
AuthorDate: 2018-06-15 13:35:41 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-06-15 15:56:24 +0000

    dev-libs/libgcrypt: stable 1.8.3 for sparc
    
    Bug: https://bugs.gentoo.org/658056
    Package-Manager: Portage-2.3.24, Repoman-2.3.6
    RepoMan-Options: --include-arches="sparc"

 dev-libs/libgcrypt/libgcrypt-1.8.3.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 5 Thomas Deutschmann (RETIRED) gentoo-dev 2018-06-17 23:30:53 UTC
x86 stable
Comment 6 Mart Raudsepp gentoo-dev 2018-06-19 14:32:18 UTC
arm64 stable
Comment 7 Larry the Git Cow gentoo-dev 2018-06-24 19:36:42 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1c0688088f71313ae7c4c2c7de55d084b9cd55fa

commit 1c0688088f71313ae7c4c2c7de55d084b9cd55fa
Author:     Sergei Trofimovich <slyfox@gentoo.org>
AuthorDate: 2018-06-24 17:54:39 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-06-24 19:36:02 +0000

    dev-libs/libgcrypt: stable 1.8.3 for ppc, bug #658056
    
    Bug: https://bugs.gentoo.org/658056
    Package-Manager: Portage-2.3.40, Repoman-2.3.9
    RepoMan-Options: --include-arches="ppc"

 dev-libs/libgcrypt/libgcrypt-1.8.3.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 8 Larry the Git Cow gentoo-dev 2018-06-24 20:21:48 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=45936e5cb1906af72f10bac2c2504243d8ac1bbb

commit 45936e5cb1906af72f10bac2c2504243d8ac1bbb
Author:     Sergei Trofimovich <slyfox@gentoo.org>
AuthorDate: 2018-06-24 20:00:51 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-06-24 20:21:04 +0000

    dev-libs/libgcrypt: stable 1.8.3 for ppc64, bug #658056
    
    Bug: https://bugs.gentoo.org/658056
    Package-Manager: Portage-2.3.40, Repoman-2.3.9
    RepoMan-Options: --include-arches="ppc64"

 dev-libs/libgcrypt/libgcrypt-1.8.3.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 9 Tobias Klausmann (RETIRED) gentoo-dev 2018-06-26 15:45:01 UTC
Stable on alpha.
Comment 10 Markus Meier gentoo-dev 2018-07-07 10:45:38 UTC
arm stable
Comment 11 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-07-16 00:12:56 UTC
s390 stable
Comment 12 Larry the Git Cow gentoo-dev 2018-07-22 09:00:39 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=aacf793a035c1d6d7ca97d5fcebb14f8bccdd4ee

commit aacf793a035c1d6d7ca97d5fcebb14f8bccdd4ee
Author:     Rolf Eike Beer <eike@sf-mail.de>
AuthorDate: 2018-07-22 08:41:25 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-07-22 09:00:09 +0000

    dev-libs/libgcrypt: stable 1.8.3 for hppa
    
    Bug: https://bugs.gentoo.org/658056
    Package-Manager: Portage-2.3.40, Repoman-2.3.9
    RepoMan-Options: --include-arches="hppa"

 dev-libs/libgcrypt/libgcrypt-1.8.3.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 13 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-09-16 08:16:10 UTC
m68k and sh stable
Comment 14 Aaron Bauman (RETIRED) gentoo-dev 2018-11-23 23:34:10 UTC
@crypto, please cleanup.
Comment 15 Larry the Git Cow gentoo-dev 2018-11-23 23:41:18 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=09cb90531cfe5b187c7ba5f2d4fb16933f78754a

commit 09cb90531cfe5b187c7ba5f2d4fb16933f78754a
Author:     Alon Bar-Lev <alonbl@gentoo.org>
AuthorDate: 2018-11-23 23:40:41 +0000
Commit:     Alon Bar-Lev <alonbl@gentoo.org>
CommitDate: 2018-11-23 23:40:41 +0000

    dev-libs/libgcrypt: cleanup old
    
    Bug: https://bugs.gentoo.org/show_bug.cgi?id=658056
    Signed-off-by: Alon Bar-Lev <alonbl@gentoo.org>
    Package-Manager: Portage-2.3.51, Repoman-2.3.11

 dev-libs/libgcrypt/Manifest                  |  2 -
 dev-libs/libgcrypt/libgcrypt-1.8.1.ebuild    | 73 ---------------------------
 dev-libs/libgcrypt/libgcrypt-1.8.2-r1.ebuild | 73 ---------------------------
 dev-libs/libgcrypt/libgcrypt-1.8.2-r2.ebuild | 75 ----------------------------
 dev-libs/libgcrypt/libgcrypt-1.8.2.ebuild    | 73 ---------------------------
 5 files changed, 296 deletions(-)