SECURITY: Fedora 37 Update: mbedtls-2.28.1-1.fc37
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2022-1dd9dc5140
2022-11-10 22:04:44.632877
--------------------------------------------------------------------------------
Name : mbedtls
Product : Fedora 37
Version : 2.28.1
Release : 1.fc37
URL : https://tls.mbed.org/
Summary : Light-weight cryptographic and SSL/TLS library
Description :
Mbed TLS is a light-weight open source cryptographic and SSL/TLS
library written in C. Mbed TLS makes it easy for developers to include
cryptographic and SSL/TLS capabilities in their (embedded)
applications with as little hassle as possible.
FOSS License Exception: https://tls.mbed.org/foss-license-exception
--------------------------------------------------------------------------------
Update Information:
Update to 2.28.1
--------------------------------------------------------------------------------
ChangeLog:
* Sat Oct 22 2022 Morten Stevens - 2.28.1-1
- Update to 2.28.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2037309 - CVE-2021-45450 mbedtls: policy bypass or oracle-based decryption [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2037309
[ 2 ] Bug #2037320 - CVE-2021-45451 mbedtls: policy bypass/oracle-based decryption in psa_aead_generate_nonce [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2037320
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-1dd9dc5140' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
A mbedtls security update has been released for Fedora 37.