Reachable Assertion in GnuTLS - CVE-2024-0567

 

Reachable Assertion in GnuTLS - CVE-2024-0567

Published: January 21, 2024


Vulnerability identifier: #VU85624
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0567
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion when verifying a certificate chain with a cycle of cross signatures. A remote attacker can pass a specially crafted certificate to the application and perform a denial of service (DoS) attack.


Affected software

GnuTLS
Oracle Solaris
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
Red Hat OpenShift Builds
Service Interconnect
OpenShift Logging
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat Migration Toolkit for Applications
OpenShift API for Data Protection (OADP)
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Storage Ceph
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libgnutls30 (Ubuntu package)
gnutls-debugsource
gnutls-help
gnutls-utils
gnutls-devel
gnutls-debuginfo
gnutls
libgnutls30-hmac
libgnutls30
libgnutls30-debuginfo
libgnutls30-hmac-32bit
libgnutls30-32bit
libgnutlsxx-devel
libgnutls30-32bit-debuginfo
libgnutlsxx28
libgnutlsxx28-debuginfo
libgnutls-devel
libgnutls30-64bit-debuginfo
gnutls-guile
libgnutls-devel-32bit
libgnutls30-hmac-64bit
libgnutls-devel-64bit
libgnutls30-64bit
gnutls-guile-debuginfo
gnutls (Red Hat package)
gnutls-doc
gnutls-dane
gnutls-c++
net-libs/gnutls
IBM Security Guardium
OpenShift Data Foundation (formerly OpenShift Container Storage)
Dell EMC VxRail Appliance

How to mitigate CVE-2024-0567

Install updates from vendor's website.

GnuTLS - update to 3.8.3
Oracle Solaris - update to 11.4 SRU 71
Red Hat OpenShift Builds - update to 1.0.1
OpenShift API for Data Protection (OADP) - update to 1.3.1
SmartFabric Storage Software - update to 1.4.3
Service Interconnect - update to 1.5.3
Cloud Pak for Network Automation - update to 2.7.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.14.17, 4.15.3
OpenShift Logging - update to 5.8.6
LANTIME Operating System Firmware (LTOS) - update to 7.08.009
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
libgnutls30 (Ubuntu package) - addressed in versions 3.6.13-2ubuntu1.10, 3.7.3-4ubuntu1.4, 3.7.8-5ubuntu1.2, 3.8.1-4ubuntu1.2
gnutls-debugsource - addressed in versions 3.7.2-10, 3.7.2-11
gnutls-help - addressed in versions 3.7.2-10, 3.7.2-11
gnutls-utils - addressed in versions 3.7.2-10, 3.7.2-11
gnutls-devel - addressed in versions 3.7.2-10, 3.7.2-11
gnutls-debuginfo - addressed in versions 3.7.2-10, 3.7.2-11
gnutls - addressed in versions 3.7.2-10, 3.7.2-11
gnutls-debuginfo - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
libgnutls30-hmac - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
gnutls-debugsource - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
gnutls - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
libgnutls30 - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
libgnutls30-debuginfo - addressed in versions 3.7.3-150400.1.3.1, 3.7.3-150400.4.41.3
libgnutls30-hmac-32bit - update to 3.7.3-150400.4.41.3
libgnutls30-32bit - update to 3.7.3-150400.4.41.3
libgnutlsxx-devel - update to 3.7.3-150400.4.41.3
libgnutls30-32bit-debuginfo - update to 3.7.3-150400.4.41.3
libgnutlsxx28 - update to 3.7.3-150400.4.41.3
libgnutlsxx28-debuginfo - update to 3.7.3-150400.4.41.3
libgnutls-devel - update to 3.7.3-150400.4.41.3
libgnutls30-64bit-debuginfo - update to 3.7.3-150400.4.41.3
gnutls-guile - update to 3.7.3-150400.4.41.3
libgnutls-devel-32bit - update to 3.7.3-150400.4.41.3
libgnutls30-hmac-64bit - update to 3.7.3-150400.4.41.3
libgnutls-devel-64bit - update to 3.7.3-150400.4.41.3
libgnutls30-64bit - update to 3.7.3-150400.4.41.3
gnutls-guile-debuginfo - update to 3.7.3-150400.4.41.3
gnutls (Red Hat package) - addressed in versions 3.7.6-21.el9_2.2, 3.7.6-23.el9_3.3
gnutls - update to 3.8.0-378
gnutls-doc - update to 3.8.2-4
gnutls-utils - update to 3.8.2-4
gnutls-devel - update to 3.8.2-4
gnutls-dane - update to 3.8.2-4
gnutls-c++ - update to 3.8.2-4
gnutls - update to 3.8.2-4
gnutls - update to 3.8.3
gnutls - addressed in versions 3.8.3-1.fc38, 3.8.3-1.fc39
net-libs/gnutls - update to 3.8.5
IBM Cloud Pak for Watson AIOps - update to 4.4.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
Red Hat Migration Toolkit for Applications - update to 6.2
Storage Ceph - update to 7.0z1
Dell EMC VxRail Appliance - update to 8.0.213

External References

Related Security Bulletins