Information Exposure Through Timing Discrepancy in GnuTLS - CVE-2024-0553
Published: January 21, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform timing attack.
The vulnerability exists due to the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. A remote attacker can perform timing sidechannel attack in RSA-PSK key exchange.
Note, the vulnerability exists due to incomplete fox for #VU83316 (CVE-2023-5981).
Affected software
Gentoo Linux
Oracle Solaris
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Slackware Linux
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
Service Interconnect
Service Telemetry Framework
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Multicluster GlobalHub
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Security Verify Governance
Red Hat OpenShift Serverless
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift API for Data Protection (OADP)
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
Dell EMC PowerProtect Data Protection
Cloud Pak for Network Automation
SmartFabric OS10
webMethods Managed File Transfer
Technical Support Appliance
PowerStore X
PowerStore T
Enterprise SONiC
Storage Ceph
IBM MQ Appliance
EMC Cloud Tiering Appliance
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
gnutls28 (Ubuntu package)
libgnutls30 (Ubuntu package)
gnutls-help
gnutls-debugsource
gnutls-debuginfo
gnutls-utils
gnutls
gnutls-devel
gnutls (Red Hat package)
gnutls-c++
gnutls-dane
libgnutls30-debuginfo
libgnutls30
libgnutls30-hmac
gnutls-guile-debuginfo
gnutls-guile
libgnutlsxx-devel
libgnutlsxx28
libgnutls30-32bit
libgnutls30-hmac-32bit
libgnutls30-32bit-debuginfo
libgnutlsxx28-debuginfo
libgnutls-devel
libgnutls30-64bit-debuginfo
libgnutls30-hmac-64bit
libgnutls-devel-32bit
libgnutls-devel-64bit
libgnutls30-64bit
gnutls-doc
net-libs/gnutls
IBM Security Guardium
IBM Qradar SIEM
Dell EMC VxRail Appliance
RSA Authentication Manager
How to mitigate CVE-2024-0553
Oracle Solaris - update to 11.4 SRU 71
Red Hat OpenShift Builds - update to 1.0.1
Red Hat OpenShift Serverless - addressed in versions 1.31.1, 1.32.0
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
SmartFabric Storage Software - update to 1.4.3
Service Interconnect - update to 1.5.3
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.10.4, 1.11, 1.11.3, 1.12.0
OpenShift Service Mesh - update to 2.5.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
Cloud Pak for Network Automation - update to 2.7.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.5, 2.9.3
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.3.5, 4.4.0
Red Hat OpenShift Container Platform - addressed in versions 4.11.59, 4.12.53, 4.14.17, 4.15.2, 4.15.3
OpenShift Logging - update to 5.8.6
LANTIME Operating System Firmware (LTOS) - update to 7.08.009
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
SmartFabric OS10 - addressed in versions 10.5.5.9, 10.5.6.1
Multicluster GlobalHub - update to 1.0.2
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Technical Support Appliance - update to 3.0.1
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.0
PowerStore X - update to 3.2.1.4-2386214
gnutls28 (Ubuntu package) - addressed in versions 3.4.10-4ubuntu1.9+esm3, 3.5.18-1ubuntu1.6+esm3, 3.6.13-2ubuntu1.12+esm2
libgnutls30 (Ubuntu package) - addressed in versions 3.6.13-2ubuntu1.10, 3.7.3-4ubuntu1.4, 3.7.8-5ubuntu1.2, 3.8.1-4ubuntu1.2
gnutls-help - addressed in versions 3.6.14-14, 3.7.2-10, 3.7.2-11
gnutls-debugsource - addressed in versions 3.6.14-14, 3.7.2-10, 3.7.2-11
gnutls-debuginfo - addressed in versions 3.6.14-14, 3.7.2-10, 3.7.2-11
gnutls-utils - addressed in versions 3.6.14-14, 3.7.2-10, 3.7.2-11
gnutls - addressed in versions 3.6.14-14, 3.7.2-10, 3.7.2-11
gnutls-devel - addressed in versions 3.6.14-14, 3.7.2-10, 3.7.2-11
gnutls (Red Hat package) - addressed in versions 3.6.16-5.el8_6.3, 3.6.16-7.el8_8.2, 3.6.16-8.el8_9.1, 3.7.6-21.el9_2.2, 3.7.6-23.el9_3.3
gnutls - addressed in versions 3.6.16-8.0.1, 3.8.2-4
gnutls-c++ - addressed in versions 3.6.16-8.0.1, 3.8.2-4
gnutls-dane - addressed in versions 3.6.16-8.0.1, 3.8.2-4
gnutls-utils - addressed in versions 3.6.16-8.0.1, 3.8.2-4
gnutls-devel - addressed in versions 3.6.16-8.0.1, 3.8.2-4
libgnutls30-debuginfo - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
libgnutls30 - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
gnutls - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
gnutls-debugsource - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
libgnutls30-hmac - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
gnutls-debuginfo - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
gnutls-guile-debuginfo - update to 3.7.3-150400.4.41.3
gnutls-guile - update to 3.7.3-150400.4.41.3
libgnutlsxx-devel - update to 3.7.3-150400.4.41.3
libgnutlsxx28 - update to 3.7.3-150400.4.41.3
libgnutls30-32bit - update to 3.7.3-150400.4.41.3
libgnutls30-hmac-32bit - update to 3.7.3-150400.4.41.3
libgnutls30-32bit-debuginfo - update to 3.7.3-150400.4.41.3
libgnutlsxx28-debuginfo - update to 3.7.3-150400.4.41.3
libgnutls-devel - update to 3.7.3-150400.4.41.3
libgnutls30-64bit-debuginfo - update to 3.7.3-150400.4.41.3
libgnutls30-hmac-64bit - update to 3.7.3-150400.4.41.3
libgnutls-devel-32bit - update to 3.7.3-150400.4.41.3
libgnutls-devel-64bit - update to 3.7.3-150400.4.41.3
libgnutls30-64bit - update to 3.7.3-150400.4.41.3
gnutls - update to 3.8.0-379
gnutls-doc - update to 3.8.2-4
gnutls - update to 3.8.3
gnutls - addressed in versions 3.8.3-1.fc38, 3.8.3-1.fc39
net-libs/gnutls - update to 3.8.5
IBM Cloud Transformation Advisor - update to 3.10.0
PowerStore T - update to 4.0.0.2-2365061
Enterprise SONiC - update to 4.2.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
Red Hat Migration Toolkit for Applications - update to 6.2
Storage Ceph - update to 7.0z1
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
Dell EMC VxRail Appliance - update to 8.0.213
RSA Authentication Manager - update to 8.7 SP2 Patch 2
IBM MQ Appliance - addressed in versions 9.3.0.21, 9.4.0.5
IBM Security Verify Governance - update to 10.0.2.0.4
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
External References
Related Security Bulletins
- Multiple vulnerabilities in GnuTLS
- Slackware Linux update for gnutls
- Ubuntu update for gnutls28
- Fedora 38 update for gnutls
- Fedora 39 update for gnutls
- Red Hat Enterprise Linux 9 update for gnutls
- Red Hat Enterprise Linux 8 update for gnutls
- Red Hat Enterprise Linux 8.8 Extended Update Support update for gnutls
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.8
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat Multicluster GlobalHub
- Multiple vulnerabilities in Red Hat Openshift distributed tracing
- SUSE update for gnutls
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Red Hat Enterprise Linux 9.2 Extended Update Support update for gnutls
- Red Hat Enterprise Linux 8.6 Extended Update Support update for gnutls
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- openEuler 22.03 LTS SP3 update for gnutls
- openEuler 20.03 LTS SP1 update for gnutls
- openEuler 22.03 LTS update for gnutls
- openEuler 22.03 LTS SP1 update for gnutls
- openEuler 22.03 LTS SP2 update for gnutls
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- openEuler 20.03 LTS SP4 update for gnutls
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.9
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift for RHEL 8
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift for RHEL 9
- SUSE update for gnutls
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Service Interconnect 1.5
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.5
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- SUSE update for gnutls
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for gnutls
- Information exposure through timing discrepancy in IBM Storage Ceph
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in IBM MQ Appliance
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in Dell PowerStore X
- IBM Technical Support Appliance update for GnuTLS
- Multiple vulnerabilities in Dell PowerStore T Family
- Anolis OS update for gnutls
- Dell SmartFabric Storage Software update for third-party components
- PowerProtect Data Protection software update for third-party components
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- RSA Authentication Manager update for third-party components
- Meinberg LANTIME firmware update for third-party components (February 2024)
- Gentoo update for GnuTLS
- Anolis OS update for gnutls
- Ubuntu update for gnutls28