Fedora Linux 8637 Published by

A mbedtls security update has been released for Fedora 36.



SECURITY: Fedora 36 Update: mbedtls-2.28.1-1.fc36


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2022-ff582c5b0d
2022-10-30 20:59:07.278892
--------------------------------------------------------------------------------

Name : mbedtls
Product : Fedora 36
Version : 2.28.1
Release : 1.fc36
URL :   https://tls.mbed.org/
Summary : Light-weight cryptographic and SSL/TLS library
Description :
Mbed TLS is a light-weight open source cryptographic and SSL/TLS
library written in C. Mbed TLS makes it easy for developers to include
cryptographic and SSL/TLS capabilities in their (embedded)
applications with as little hassle as possible.
FOSS License Exception:   https://tls.mbed.org/foss-license-exception

--------------------------------------------------------------------------------
Update Information:

Update to 2.28.1
--------------------------------------------------------------------------------
ChangeLog:

* Sat Oct 22 2022 Morten Stevens - 2.28.1-1
- Update to 2.28.1
* Thu Jul 21 2022 Fedora Release Engineering - 2.28.0-3
- Rebuilt for   https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2037309 - CVE-2021-45450 mbedtls: policy bypass or oracle-based decryption [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2037309
[ 2 ] Bug #2037320 - CVE-2021-45451 mbedtls: policy bypass/oracle-based decryption in psa_aead_generate_nonce [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2037320
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-ff582c5b0d' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________