Memory leak in gnutls — ref:_00D1igLOd._500Tr6tLDN:ref
VUL-0: CVE-2024-28834: gnutls: side-channel in the deterministic ECDSA
VUL-0: CVE-2024-28835: gnutls: certtool crash when verifying a certificate chain
pmonrealgonzalez
important
security
Security update for gnutls
This update for gnutls fixes the following issues:
- CVE-2024-28835: certtool crash when verifying a certificate chain (bsc#1221747)
- CVE-2024-28834: Fixed side-channel in the deterministic ECDSA (bsc#1221746)
- jitterentropy: Release the memory of the entropy collector when using jitterentropy
with phtreads as there is also a pre-initialization done in the main thread. (bsc#1221242)
gnutls