Fedora Linux 8811 Published by

A rust-aes-gcm security update has been released for Fedora 38.

[SECURITY] Fedora 38 Update: rust-aes-gcm-0.10.3-1.fc38

Fedora Update Notification
2023-10-03 02:21:55.690578

Name : rust-aes-gcm
Product : Fedora 38
Version : 0.10.3
Release : 1.fc38
URL : https://crates.io/crates/aes-gcm
Summary : Pure Rust implementation of the AES-GCM AEAD Cipher
Description :
Pure Rust implementation of the AES-GCM (Galois/Counter Mode)
Authenticated Encryption with Associated Data (AEAD) Cipher with
optional architecture-specific hardware acceleration.

Update Information:

- Update the aes-gcm crate to version 0.10.3. Addresses CVE-2023-42811. -
Rebuild dependent packages (firecracker) for aes-gcm v0.10.3.

* Sun Sep 24 2023 Fabio Valentini [decathorpe@gmail.com] - 0.10.3-1
- Update to version 0.10.3; Fixes RHBZ#2240136
* Fri Jul 21 2023 Fedora Release Engineering [releng@fedoraproject.org] - 0.10.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

[ 1 ] Bug #2240269 - CVE-2023-42811 rust-aes-gcm: aes-gcm: Plaintext exposed in decrypt_in_place_detached even on tag verification failure [fedora-all]

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-98f44d1c4c' at the command
line. For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at