Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2023:1141 - Security Advisory
Issued:
2023-03-07
Updated:
2023-03-07

RHSA-2023:1141 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: gnutls security and bug fix update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gnutls is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.

Security Fix(es):

  • gnutls: timing side-channel in the TLS RSA key exchange code (CVE-2023-0361)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • CCM tag length should be limited to known values (BZ#2144535)
  • In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator (BZ#2144537)
  • dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode (BZ#2149640)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2144537 - In FIPS mode, gnutls should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator [rhel-9.1.0.z]
  • BZ - 2149640 - dracut-cmdline[554]: Error in GnuTLS initialization: Error while performing self checks i FIPS mode [rhel-9.1.0.z]
  • BZ - 2162596 - CVE-2023-0361 gnutls: timing side-channel in the TLS RSA key exchange code

CVEs

  • CVE-2023-0361

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
gnutls-3.7.6-18.el9_1.src.rpm SHA-256: afce0383a39b5ed2651e534b7851c2b70fc5f5dd2c244b972ad2b8ff5be70bdd
x86_64
gnutls-3.7.6-18.el9_1.i686.rpm SHA-256: 17e632a6cdf8b364850b58c26432a253306d37e3682f1fdcd8a8cee59c72f4bc
gnutls-3.7.6-18.el9_1.x86_64.rpm SHA-256: 45f1784bcbc7e98e522bceff508414b473f31adab71ea4dc390db04bb25b820d
gnutls-c++-3.7.6-18.el9_1.i686.rpm SHA-256: b1e3dbd1277f1e0d3ff0675163653d2225abc33d0db40e8e5259d1fa2844b6f5
gnutls-c++-3.7.6-18.el9_1.x86_64.rpm SHA-256: e08f3587128e4ba2a553f6c9eb0438268db2ed10ac83278535d7acbd334a6c1e
gnutls-c++-debuginfo-3.7.6-18.el9_1.i686.rpm SHA-256: ce5037143cf56465815663121420df0503d6c7be9e1b88bcca282fd50a7f9bf9
gnutls-c++-debuginfo-3.7.6-18.el9_1.i686.rpm SHA-256: ce5037143cf56465815663121420df0503d6c7be9e1b88bcca282fd50a7f9bf9
gnutls-c++-debuginfo-3.7.6-18.el9_1.x86_64.rpm SHA-256: 3bcd4236eb9b3dd60025dff9ccc779872b8a33cc691d4843d7b2f61a03c045f3
gnutls-c++-debuginfo-3.7.6-18.el9_1.x86_64.rpm SHA-256: 3bcd4236eb9b3dd60025dff9ccc779872b8a33cc691d4843d7b2f61a03c045f3
gnutls-dane-3.7.6-18.el9_1.i686.rpm SHA-256: 7627167896991c089bd5379481c77366ea16a7e08ba91cd90faaf6fa4a7cd1ee
gnutls-dane-3.7.6-18.el9_1.x86_64.rpm SHA-256: e6ec59f25ed86fbbfe36f6abfefeb84ef13e5af3e0e25446bc62a880fb5c4561
gnutls-dane-debuginfo-3.7.6-18.el9_1.i686.rpm SHA-256: efe4cc330a0d8bfab2ff4d8fbb71cebd0d87a3d2dcbb499628bf8e51a7c0619f
gnutls-dane-debuginfo-3.7.6-18.el9_1.i686.rpm SHA-256: efe4cc330a0d8bfab2ff4d8fbb71cebd0d87a3d2dcbb499628bf8e51a7c0619f
gnutls-dane-debuginfo-3.7.6-18.el9_1.x86_64.rpm SHA-256: 30793263127141c42c230d9ecf30478aa6f01eeefa30cd64c64860f3679a5909
gnutls-dane-debuginfo-3.7.6-18.el9_1.x86_64.rpm SHA-256: 30793263127141c42c230d9ecf30478aa6f01eeefa30cd64c64860f3679a5909
gnutls-debuginfo-3.7.6-18.el9_1.i686.rpm SHA-256: f5acd640f1195cf95e04ba9779d7ff3b1352d42f6c307857970b2037ed8fb578
gnutls-debuginfo-3.7.6-18.el9_1.i686.rpm SHA-256: f5acd640f1195cf95e04ba9779d7ff3b1352d42f6c307857970b2037ed8fb578
gnutls-debuginfo-3.7.6-18.el9_1.x86_64.rpm SHA-256: b495006572b375106ecc5a368c9c8bcd4a1fe2d82596f31e4455542450fa0f0a
gnutls-debuginfo-3.7.6-18.el9_1.x86_64.rpm SHA-256: b495006572b375106ecc5a368c9c8bcd4a1fe2d82596f31e4455542450fa0f0a
gnutls-debugsource-3.7.6-18.el9_1.i686.rpm SHA-256: a5ecb6b69c6277b0e393f9fbde6dcb017a112f55e8103949fa4d99e77abe585c
gnutls-debugsource-3.7.6-18.el9_1.i686.rpm SHA-256: a5ecb6b69c6277b0e393f9fbde6dcb017a112f55e8103949fa4d99e77abe585c
gnutls-debugsource-3.7.6-18.el9_1.x86_64.rpm SHA-256: 381e2082f55ccf21381f410585c34ec30e60fd1d1cdbc6065a74fd32cbd9e32c
gnutls-debugsource-3.7.6-18.el9_1.x86_64.rpm SHA-256: 381e2082f55ccf21381f410585c34ec30e60fd1d1cdbc6065a74fd32cbd9e32c
gnutls-devel-3.7.6-18.el9_1.i686.rpm SHA-256: 032543b312ab5fdcd484ece290bc97c71c535876f7a4c731e4b4e8b8ae88b37c
gnutls-devel-3.7.6-18.el9_1.x86_64.rpm SHA-256: 2dafc84d42967eab826d16509e727f96c4b83a0b2548c0a7b975fc7de2e5ee51
gnutls-utils-3.7.6-18.el9_1.x86_64.rpm SHA-256: 565929ba23876aa595e7af0a5b603a41222939ad9d46e83f9b553db5eae58fdb
gnutls-utils-debuginfo-3.7.6-18.el9_1.i686.rpm SHA-256: 70a0b28e837bad4383f1de131ca6084ea051f53ed0f91b3b8f18ac9753b8d397
gnutls-utils-debuginfo-3.7.6-18.el9_1.i686.rpm SHA-256: 70a0b28e837bad4383f1de131ca6084ea051f53ed0f91b3b8f18ac9753b8d397
gnutls-utils-debuginfo-3.7.6-18.el9_1.x86_64.rpm SHA-256: f427bbd22293e836ed7603498c3c76fb5cbdf28428a5ff2e5f07d589e3aeecd1
gnutls-utils-debuginfo-3.7.6-18.el9_1.x86_64.rpm SHA-256: f427bbd22293e836ed7603498c3c76fb5cbdf28428a5ff2e5f07d589e3aeecd1

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
gnutls-3.7.6-18.el9_1.src.rpm SHA-256: afce0383a39b5ed2651e534b7851c2b70fc5f5dd2c244b972ad2b8ff5be70bdd
s390x
gnutls-3.7.6-18.el9_1.s390x.rpm SHA-256: 6f6680a493f2480d53c27b2ba30e6c9ef8b9c0c92664fa575f06486e4563883c
gnutls-c++-3.7.6-18.el9_1.s390x.rpm SHA-256: 2d168342c90da3070875556959a9d5914ae14dccac0b6797d873d02764c6a533
gnutls-c++-debuginfo-3.7.6-18.el9_1.s390x.rpm SHA-256: 41507326c9a617b4a39b3895a8115d21ce1074793d1e4b97153cf2302b61d0b2
gnutls-c++-debuginfo-3.7.6-18.el9_1.s390x.rpm SHA-256: 41507326c9a617b4a39b3895a8115d21ce1074793d1e4b97153cf2302b61d0b2
gnutls-dane-3.7.6-18.el9_1.s390x.rpm SHA-256: 0d9f9fdfb05d8cf774b40e271edec1e347bbb75fc2f68218ff06d5a6725971b4
gnutls-dane-debuginfo-3.7.6-18.el9_1.s390x.rpm SHA-256: 45fd86f7bdcb2fc4ed9eb384cab7aeb3915842f40e37737a612ade69c06665b3
gnutls-dane-debuginfo-3.7.6-18.el9_1.s390x.rpm SHA-256: 45fd86f7bdcb2fc4ed9eb384cab7aeb3915842f40e37737a612ade69c06665b3
gnutls-debuginfo-3.7.6-18.el9_1.s390x.rpm SHA-256: 16365522de5a79146412f647a0e7642678d1f997dd244614f2d2fce260dfadb1
gnutls-debuginfo-3.7.6-18.el9_1.s390x.rpm SHA-256: 16365522de5a79146412f647a0e7642678d1f997dd244614f2d2fce260dfadb1
gnutls-debugsource-3.7.6-18.el9_1.s390x.rpm SHA-256: 628cdba636a4b2d300555cf43bcd380ac07cd80d127136db183892fce246bbf5
gnutls-debugsource-3.7.6-18.el9_1.s390x.rpm SHA-256: 628cdba636a4b2d300555cf43bcd380ac07cd80d127136db183892fce246bbf5
gnutls-devel-3.7.6-18.el9_1.s390x.rpm SHA-256: baa6722261962ca84ff7912f9d70788275d1897e020e90655b8e605f7dc0f6d9
gnutls-utils-3.7.6-18.el9_1.s390x.rpm SHA-256: ce8496eaaabc251e50c9f0c31d86239b14fc87c1d6919f405ba209cfea7da8e5
gnutls-utils-debuginfo-3.7.6-18.el9_1.s390x.rpm SHA-256: b11901f7c5425fefe15203752935b3f274c2d7fce55a39e0d24613803968b747
gnutls-utils-debuginfo-3.7.6-18.el9_1.s390x.rpm SHA-256: b11901f7c5425fefe15203752935b3f274c2d7fce55a39e0d24613803968b747

Red Hat Enterprise Linux for Power, little endian 9

SRPM
gnutls-3.7.6-18.el9_1.src.rpm SHA-256: afce0383a39b5ed2651e534b7851c2b70fc5f5dd2c244b972ad2b8ff5be70bdd
ppc64le
gnutls-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 98e6d7c42b6d4935aff5adb799ce12bd06bd646f685bec69fb73790c33746a0d
gnutls-c++-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 25408920d07e19064f3dc9271795d85e18b915dbaab1c2c51cabef6548548651
gnutls-c++-debuginfo-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 570519de5071193305b355689f62a3d7476690b287996bb2a9e4f3cd92341732
gnutls-c++-debuginfo-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 570519de5071193305b355689f62a3d7476690b287996bb2a9e4f3cd92341732
gnutls-dane-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 19590cf87c6f18fc74b1412c88e6225310414f3e12d5d3cf44ee8cf6f3518005
gnutls-dane-debuginfo-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 2eed5b2f645b6cc0e4809582c29a8cfe27e0d574640b9726359c7b959e67f0ce
gnutls-dane-debuginfo-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 2eed5b2f645b6cc0e4809582c29a8cfe27e0d574640b9726359c7b959e67f0ce
gnutls-debuginfo-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 11f004d982a12266b27e52defb1133b1015ac69f3fe960b7625dd8e411015e27
gnutls-debuginfo-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 11f004d982a12266b27e52defb1133b1015ac69f3fe960b7625dd8e411015e27
gnutls-debugsource-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 6e095fb23af67c9a1010d8f65170b1d97aa6f9c9115ea6a64450abbd42e4a4b5
gnutls-debugsource-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 6e095fb23af67c9a1010d8f65170b1d97aa6f9c9115ea6a64450abbd42e4a4b5
gnutls-devel-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 2f4078e1c388293e1718be6d27edfc14ec98f73eae9e6f3d44f3822770ffb0ea
gnutls-utils-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 5942f0e98e1084a137aa087171ac5a3970b67efa4fa486575df813fea39da0ed
gnutls-utils-debuginfo-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 9277fd2f97c776c95a64e0e98379270c2e92d95e94c9dd676df9bbaecbadd3f1
gnutls-utils-debuginfo-3.7.6-18.el9_1.ppc64le.rpm SHA-256: 9277fd2f97c776c95a64e0e98379270c2e92d95e94c9dd676df9bbaecbadd3f1

Red Hat Enterprise Linux for ARM 64 9

SRPM
gnutls-3.7.6-18.el9_1.src.rpm SHA-256: afce0383a39b5ed2651e534b7851c2b70fc5f5dd2c244b972ad2b8ff5be70bdd
aarch64
gnutls-3.7.6-18.el9_1.aarch64.rpm SHA-256: 0c9fe253555aff46b05cc3e832148380bd9c62c6e90d4e73804fa78c420c2e1e
gnutls-c++-3.7.6-18.el9_1.aarch64.rpm SHA-256: 46d552ef0e27388ff9fddb2e6d128d3d1825b73f0ae6b20ed6f7dc96eb725c91
gnutls-c++-debuginfo-3.7.6-18.el9_1.aarch64.rpm SHA-256: 113796cfaedef1f1b96949c9a690ee5d67ee302460d916f0fe027a138195d0f3
gnutls-c++-debuginfo-3.7.6-18.el9_1.aarch64.rpm SHA-256: 113796cfaedef1f1b96949c9a690ee5d67ee302460d916f0fe027a138195d0f3
gnutls-dane-3.7.6-18.el9_1.aarch64.rpm SHA-256: 5b034d252d24ecd007390fc1b43d97613579682f72b36e8aa377ff271fbc2697
gnutls-dane-debuginfo-3.7.6-18.el9_1.aarch64.rpm SHA-256: a00ccc9c3df364a91989c154b48c379af07b5123a9fe23f5a5b1aecaa31a8587
gnutls-dane-debuginfo-3.7.6-18.el9_1.aarch64.rpm SHA-256: a00ccc9c3df364a91989c154b48c379af07b5123a9fe23f5a5b1aecaa31a8587
gnutls-debuginfo-3.7.6-18.el9_1.aarch64.rpm SHA-256: f3e19457f458f4965aff9985d2a34569ac93364947f4acd31f5f0fb3469d61e7
gnutls-debuginfo-3.7.6-18.el9_1.aarch64.rpm SHA-256: f3e19457f458f4965aff9985d2a34569ac93364947f4acd31f5f0fb3469d61e7
gnutls-debugsource-3.7.6-18.el9_1.aarch64.rpm SHA-256: 9bc9695fe41d65e4f1e491962958e1dd92fdff759ee60dd69f6126ea5dd913ca
gnutls-debugsource-3.7.6-18.el9_1.aarch64.rpm SHA-256: 9bc9695fe41d65e4f1e491962958e1dd92fdff759ee60dd69f6126ea5dd913ca
gnutls-devel-3.7.6-18.el9_1.aarch64.rpm SHA-256: f992abdbe814b62474c9555349afbc2deca99677fb512393ca48920bd3bb0fad
gnutls-utils-3.7.6-18.el9_1.aarch64.rpm SHA-256: 7d5ddc19f1bea3ebe81dbf977e473f58b3b9c85b7a79ba7c72f33824fdb5d643
gnutls-utils-debuginfo-3.7.6-18.el9_1.aarch64.rpm SHA-256: 1a0d480287517247731dbbc2cfbfc6ca3c93d652cfe4281aa63dd5d48079a49d
gnutls-utils-debuginfo-3.7.6-18.el9_1.aarch64.rpm SHA-256: 1a0d480287517247731dbbc2cfbfc6ca3c93d652cfe4281aa63dd5d48079a49d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter