CVE-2024-28834
Published: 21 March 2024
A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.
Notes
Author | Note |
---|---|
mdeslaur | per Debian, introduced in 3.6.10 |
Priority
Status
Package | Release | Status |
---|---|---|
gnutls28 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Released
(3.6.13-2ubuntu1.11)
|
|
jammy |
Released
(3.7.3-4ubuntu1.5)
|
|
mantic |
Released
(3.8.1-4ubuntu1.3)
|
|
noble |
Released
(3.8.3-1.1ubuntu3.1)
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
(code not present)
|
|
Patches: upstream: https://gitlab.com/gnutls/gnutls/-/commit/4a4cefef6c194f8fbbffd7fb19651219421b085b upstream: https://gitlab.com/gnutls/gnutls/-/commit/1c4701ffc342259fc5965d5a0de90d87f780e3e5 |
References
- https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2023-12-04
- https://access.redhat.com/security/cve/CVE-2024-28834
- https://people.redhat.com/~hkario/marvin/
- https://www.cve.org/CVERecord?id=CVE-2024-28834
- https://ubuntu.com/security/notices/USN-6733-1
- https://ubuntu.com/security/notices/USN-6733-2
- NVD
- Launchpad
- Debian