Fedora Linux 8562 Published by

A mbedtls security update has been released for Fedora 31.



SECURITY: Fedora 31 Update: mbedtls-2.16.6-1.fc31


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2020-42564738a1
2020-06-05 02:39:48.632782
--------------------------------------------------------------------------------

Name : mbedtls
Product : Fedora 31
Version : 2.16.6
Release : 1.fc31
URL :   https://tls.mbed.org/
Summary : Light-weight cryptographic and SSL/TLS library
Description :
Mbed TLS is a light-weight open source cryptographic and SSL/TLS
library written in C. Mbed TLS makes it easy for developers to include
cryptographic and SSL/TLS capabilities in their (embedded)
applications with as little hassle as possible.
FOSS License Exception:   https://tls.mbed.org/foss-license-exception

--------------------------------------------------------------------------------
Update Information:

- Update to 2.16.6 Release notes:   https://tls.mbed.org/tech-
updates/releases/mbedtls-2.16.6-and-2.7.15-released Security Advisory:
  https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-
advisory-2020-04
--------------------------------------------------------------------------------
ChangeLog:

* Wed May 27 2020 Morten Stevens - 2.16.6-1
- Update to 2.16.6
- Security Advisory 2020-04 (CVE-2020-10932)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1838551 - CVE-2020-10932 mbedtls: side channel attack possibly leading to information disclosure [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1838551
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2020-42564738a1' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys