{"id":"MGASA-2024-0037","summary":"Updated mbedtls packages fix security vulnerabilities","details":"This update brings the mbedtls packages from 2.28.3 to the latest 2.28.7\nrelease in the LTS branch, fixing a number of bugs as well the following\nsecurity vulnerabilities:\n- Buffer overread in TLS stream cipher suites.\n- Timing side channel in private key RSA operations.\n- Buffer overflow in mbedtls_x509_set_extension.\nSee the linked release notes for details.\n","modified":"2026-04-16T04:23:12.986266Z","published":"2024-02-14T23:02:34Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0037.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32844"},{"type":"WEB","url":"https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.4"},{"type":"WEB","url":"https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.5"},{"type":"WEB","url":"https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-2.28.5"},{"type":"WEB","url":"https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.6"},{"type":"WEB","url":"https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7"},{"type":"ADVISORY","url":"https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2023-10-1/"},{"type":"ADVISORY","url":"https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-1/"},{"type":"ADVISORY","url":"https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/"}],"affected":[{"package":{"name":"mbedtls","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/mbedtls?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.28.7-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0037.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}