Upstream information

CVE-2024-23170 at MITRE

Description

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v3 Scores
  National Vulnerability Database
Base Score 5.5
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
CVSSv3 Version 3.1
SUSE Bugzilla entry: 1219336 [IN_PROGRESS]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 15 SP5
  • libmbedcrypto7 >= 2.28.7-bp155.2.3.1
  • libmbedcrypto7-32bit >= 2.28.7-bp155.2.3.1
  • libmbedcrypto7-64bit >= 2.28.7-bp155.2.3.1
  • libmbedtls14 >= 2.28.7-bp155.2.3.1
  • libmbedtls14-32bit >= 2.28.7-bp155.2.3.1
  • libmbedtls14-64bit >= 2.28.7-bp155.2.3.1
  • libmbedx509-1 >= 2.28.7-bp155.2.3.1
  • libmbedx509-1-32bit >= 2.28.7-bp155.2.3.1
  • libmbedx509-1-64bit >= 2.28.7-bp155.2.3.1
  • mbedtls-devel >= 2.28.7-bp155.2.3.1
Patchnames:
openSUSE-2024-37
openSUSE Leap 15.5
  • libmbedcrypto7 >= 2.28.7-bp155.2.3.1
  • libmbedcrypto7-32bit >= 2.28.7-bp155.2.3.1
  • libmbedcrypto7-64bit >= 2.28.7-bp155.2.3.1
  • libmbedtls14 >= 2.28.7-bp155.2.3.1
  • libmbedtls14-32bit >= 2.28.7-bp155.2.3.1
  • libmbedtls14-64bit >= 2.28.7-bp155.2.3.1
  • libmbedx509-1 >= 2.28.7-bp155.2.3.1
  • libmbedx509-1-32bit >= 2.28.7-bp155.2.3.1
  • libmbedx509-1-64bit >= 2.28.7-bp155.2.3.1
  • mbedtls-devel >= 2.28.7-bp155.2.3.1
Patchnames:
openSUSE-2024-37
openSUSE Tumbleweed
  • libeverest >= 3.5.2-1.1
  • libeverest-x86-64-v3 >= 3.5.2-1.1
  • libmbedcrypto15 >= 3.5.2-1.1
  • libmbedcrypto15-x86-64-v3 >= 3.5.2-1.1
  • libmbedcrypto7 >= 2.28.7-1.1
  • libmbedcrypto7-x86-64-v3 >= 2.28.7-1.1
  • libmbedtls14 >= 2.28.7-1.1
  • libmbedtls14-x86-64-v3 >= 2.28.7-1.1
  • libmbedtls20 >= 3.5.2-1.1
  • libmbedtls20-x86-64-v3 >= 3.5.2-1.1
  • libmbedx509-1 >= 2.28.7-1.1
  • libmbedx509-1-x86-64-v3 >= 2.28.7-1.1
  • libmbedx509-6 >= 3.5.2-1.1
  • libmbedx509-6-x86-64-v3 >= 3.5.2-1.1
  • libp256m >= 3.5.2-1.1
  • libp256m-x86-64-v3 >= 3.5.2-1.1
  • mbedtls-2-devel >= 2.28.7-1.1
  • mbedtls-devel >= 3.5.2-1.1
Patchnames:
openSUSE Tumbleweed GA libeverest-3.5.2-1.1
openSUSE Tumbleweed GA libmbedcrypto7-2.28.7-1.1


SUSE Timeline for this CVE

CVE page created: Mon Jan 29 23:00:09 2024
CVE page last modified: Thu Apr 11 19:38:35 2024