UbuntuUpdates.org

Latest Changelogs for all releases

All releases Jammy Noble Plucky Resolute
Include all PPAs Exclude daily builds PPAs Exclude all PPAs
Include levels: securityupdatesproposedbackportsbase

Note: Only updates for "head" packages where the changelog is available are shown on this page (view all).

pyasn1 Sep 1st 18:07
Release: resolute Repo: main Level: security New version: 0.6.3-1ubuntu0.1
Packages in group:  python3-pyasn1 python-pyasn1-doc

pyasn1 (0.6.3-1ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
    unbounded long-form tag IDs
    - debian/patches/CVE-2026-59886.patch: Merge commit from fork in
      pyasn1/type/univ.py, tests/codec/ber/test_decoder.py,
      tests/codec/cer/test_decoder.py, tests/codec/der/test_decoder.py,
      tests/type/test_univ.py.
    - CVE-2026-59886
  * SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER and
    RELATIVE-OID processing allows denial of service
    - debian/patches/CVE-2026-59884.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/type/tag.py,
      tests/codec/ber/test_decoder.py, tests/codec/cer/test_decoder.py,
      tests/codec/der/test_decoder.py, tests/type/test_tag.py.
    - CVE-2026-59884
  * SECURITY UPDATE: Uncontrolled resource consumption when converting
    decoded REAL values
    - debian/patches/CVE-2026-59885.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/codec/ber/encoder.py,
      tests/codec/ber/test_decoder.py, tests/codec/ber/test_encoder.py.
    - CVE-2026-59885

 -- Marc Deslauriers Thu, 20 Aug 2026 13:20:40 -0400

CVE-2026-59886 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u
CVE-2026-59884 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating
CVE-2026-59885 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua

libevent Sep 1st 18:07
Release: noble Repo: main Level: updates New version: 2.1.12-stable-9ubuntu2.1
Packages in group:  libevent-2.1-7t64 libevent-core-2.1-7t64 libevent-dev libevent-extra-2.1-7t64 libevent-openssl-2.1-7t64 libevent-pthreads-2.1-7t64

libevent (2.1.12-stable-9ubuntu2.1) noble-security; urgency=medium

  * SECURITY UPDATE: dangling pointer in buffer reference handling
    - debian/patches/CVE-2026-63381.patch: reset empty output buffer
      pointers and add regression coverage in buffer.c and
      test/regress_buffer.c.
    - CVE-2026-63381
  * SECURITY UPDATE: HTTP request smuggling in request body framing
    - debian/patches/CVE-2026-63382_1.patch: require strict CRLF chunk
      delimiters in http.c.
    - debian/patches/CVE-2026-63382_2.patch: validate transfer encodings
      and add tests in http-internal.h, http.c, and test/regress_http.c.
    - CVE-2026-63382
  * SECURITY UPDATE: out-of-bounds read during RPC tag decoding
    - debian/patches/CVE-2026-63383.patch: bound tag decoding to contiguous
      buffer data in event_tagging.c.
    - CVE-2026-63383
  * SECURITY UPDATE: integer overflow during RPC payload length decoding
    - debian/patches/CVE-2026-63384.patch: reject oversized RPC payload
      lengths in event_tagging.c and document the limit in
      include/event2/tag.h.
    - CVE-2026-63384
  * SECURITY UPDATE: HTTP header injection during folded header handling
    - debian/patches/CVE-2026-63385.patch: reject CR and LF in HTTP header
      values and update tests in http.c and test/regress_http.c.
    - CVE-2026-63385

 -- Shafayat Hossain Majumder Fri, 28 Aug 2026 16:44:18 -0400

CVE-2026-63381 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_refere
CVE-2026-63382 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra
CVE-2026-63383 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c
CVE-2026-63384 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evta
CVE-2026-63385 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int

ncurses Sep 1st 18:07
Release: noble Repo: main Level: updates New version: 6.4+20240113-1ubuntu2.2
Packages in group:  lib32ncurses6 lib32ncurses-dev lib32ncursesw6 lib32tinfo6 libncurses6 libncurses-dev libncursesw6 libtinfo6 ncurses-base ncurses-bin ncurses-doc (... see all)

ncurses (6.4+20240113-1ubuntu2.2) noble-security; urgency=medium

  * SECURITY UPDATE: Stack-based buffer overflow
    - debian/patches/CVE-2025-6141.patch: add a buffer-limit check in
      postprocess_termcap in ncurses/tinfo/parse_entry.c.
    - CVE-2025-6141

 -- John Breton Mon, 31 Aug 2026 07:36:06 -0400

CVE-2025-6141 A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_t

pyasn1 Sep 1st 18:07
Release: noble Repo: main Level: security New version: 0.4.8-4ubuntu0.3
Packages in group:  python3-pyasn1 python-pyasn1-doc

pyasn1 (0.4.8-4ubuntu0.3) noble-security; urgency=medium

  * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
    unbounded long-form tag IDs
    - debian/patches/CVE-2026-59886.patch: Merge commit from fork in
      pyasn1/type/univ.py, tests/codec/ber/test_decoder.py,
      tests/codec/cer/test_decoder.py, tests/codec/der/test_decoder.py,
      tests/type/test_univ.py.
    - CVE-2026-59886
  * SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER and
    RELATIVE-OID processing allows denial of service
    - debian/patches/CVE-2026-59884.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/type/tag.py,
      tests/codec/ber/test_decoder.py, tests/codec/cer/test_decoder.py,
      tests/codec/der/test_decoder.py, tests/type/test_tag.py.
    - CVE-2026-59884
  * SECURITY UPDATE: Uncontrolled resource consumption when converting
    decoded REAL values
    - debian/patches/CVE-2026-59885.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/codec/ber/encoder.py,
      tests/codec/ber/test_decoder.py, tests/codec/ber/test_encoder.py.
    - CVE-2026-59885

 -- Marc Deslauriers Thu, 20 Aug 2026 13:36:50 -0400

CVE-2026-59886 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u
CVE-2026-59884 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating
CVE-2026-59885 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua

ncurses Sep 1st 18:07
Release: jammy Repo: universe Level: updates New version: 6.3-2ubuntu0.3
Packages in group:  libncurses5 libncursesw5 libtinfo5

ncurses (6.3-2ubuntu0.3) jammy-security; urgency=medium

  * SECURITY UPDATE: Stack-based buffer overflow
    - debian/patches/CVE-2025-6141.patch: add a buffer-limit check in
      postprocess_termcap in ncurses/tinfo/parse_entry.c.
    - CVE-2025-6141

 -- John Breton Mon, 31 Aug 2026 07:36:57 -0400

CVE-2025-6141 A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_t

pyasn1 Sep 1st 18:07
Release: jammy Repo: universe Level: security New version: 0.4.8-1ubuntu0.3
Packages in group:  pypy-pyasn1

pyasn1 (0.4.8-1ubuntu0.3) jammy-security; urgency=medium

  * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
    unbounded long-form tag IDs
    - debian/patches/CVE-2026-59886.patch: Merge commit from fork in
      pyasn1/type/univ.py, tests/codec/ber/test_decoder.py,
      tests/codec/cer/test_decoder.py, tests/codec/der/test_decoder.py,
      tests/type/test_univ.py.
    - CVE-2026-59886
  * SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER and
    RELATIVE-OID processing allows denial of service
    - debian/patches/CVE-2026-59884.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/type/tag.py,
      tests/codec/ber/test_decoder.py, tests/codec/cer/test_decoder.py,
      tests/codec/der/test_decoder.py, tests/type/test_tag.py.
    - CVE-2026-59884
  * SECURITY UPDATE: Uncontrolled resource consumption when converting
    decoded REAL values
    - debian/patches/CVE-2026-59885.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/codec/ber/encoder.py,
      tests/codec/ber/test_decoder.py, tests/codec/ber/test_encoder.py.
    - CVE-2026-59885

 -- Marc Deslauriers Thu, 20 Aug 2026 18:00:34 -0400

CVE-2026-59886 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u
CVE-2026-59884 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating
CVE-2026-59885 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua

libevent Sep 1st 18:07
Release: jammy Repo: main Level: updates New version: 2.1.12-stable-1ubuntu0.1
Packages in group:  libevent-2.1-7 libevent-core-2.1-7 libevent-dev libevent-extra-2.1-7 libevent-openssl-2.1-7 libevent-pthreads-2.1-7

libevent (2.1.12-stable-1ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: dangling pointer in buffer reference handling
    - debian/patches/CVE-2026-63381.patch: reset empty output buffer
      pointers and add regression coverage in buffer.c and
      test/regress_buffer.c.
    - CVE-2026-63381
  * SECURITY UPDATE: HTTP request smuggling in request body framing
    - debian/patches/CVE-2026-63382_1.patch: require strict CRLF chunk
      delimiters in http.c.
    - debian/patches/CVE-2026-63382_2.patch: validate transfer encodings
      and add tests in http-internal.h, http.c, and test/regress_http.c.
    - CVE-2026-63382
  * SECURITY UPDATE: out-of-bounds read during RPC tag decoding
    - debian/patches/CVE-2026-63383.patch: bound tag decoding to contiguous
      buffer data in event_tagging.c.
    - CVE-2026-63383
  * SECURITY UPDATE: integer overflow during RPC payload length decoding
    - debian/patches/CVE-2026-63384.patch: reject oversized RPC payload
      lengths in event_tagging.c and document the limit in
      include/event2/tag.h.
    - CVE-2026-63384
  * SECURITY UPDATE: HTTP header injection during folded header handling
    - debian/patches/CVE-2026-63385.patch: reject CR and LF in HTTP header
      values and update tests in http.c and test/regress_http.c.
    - CVE-2026-63385

 -- Shafayat Hossain Majumder Fri, 28 Aug 2026 16:44:15 -0400

CVE-2026-63381 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_refere
CVE-2026-63382 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra
CVE-2026-63383 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c
CVE-2026-63384 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evta
CVE-2026-63385 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int

ncurses Sep 1st 18:07
Release: jammy Repo: main Level: updates New version: 6.3-2ubuntu0.3
Packages in group:  lib32ncurses6 lib32ncurses-dev lib32ncursesw6 lib32tinfo6 libncurses5-dev libncurses6 libncurses-dev libncursesw5-dev libncursesw6 libtinfo6 libtinfo-dev (... see all)

ncurses (6.3-2ubuntu0.3) jammy-security; urgency=medium

  * SECURITY UPDATE: Stack-based buffer overflow
    - debian/patches/CVE-2025-6141.patch: add a buffer-limit check in
      postprocess_termcap in ncurses/tinfo/parse_entry.c.
    - CVE-2025-6141

 -- John Breton Mon, 31 Aug 2026 07:36:57 -0400

CVE-2025-6141 A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_t

pyasn1 Sep 1st 18:07
Release: jammy Repo: main Level: security New version: 0.4.8-1ubuntu0.3
Packages in group:  python3-pyasn1 python-pyasn1-doc

pyasn1 (0.4.8-1ubuntu0.3) jammy-security; urgency=medium

  * SECURITY UPDATE: pyasn1 BER/CER/DER decoder denial of service via
    unbounded long-form tag IDs
    - debian/patches/CVE-2026-59886.patch: Merge commit from fork in
      pyasn1/type/univ.py, tests/codec/ber/test_decoder.py,
      tests/codec/cer/test_decoder.py, tests/codec/der/test_decoder.py,
      tests/type/test_univ.py.
    - CVE-2026-59886
  * SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER and
    RELATIVE-OID processing allows denial of service
    - debian/patches/CVE-2026-59884.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/type/tag.py,
      tests/codec/ber/test_decoder.py, tests/codec/cer/test_decoder.py,
      tests/codec/der/test_decoder.py, tests/type/test_tag.py.
    - CVE-2026-59884
  * SECURITY UPDATE: Uncontrolled resource consumption when converting
    decoded REAL values
    - debian/patches/CVE-2026-59885.patch: Merge commit from fork in
      pyasn1/codec/ber/decoder.py, pyasn1/codec/ber/encoder.py,
      tests/codec/ber/test_decoder.py, tests/codec/ber/test_encoder.py.
    - CVE-2026-59885

 -- Marc Deslauriers Thu, 20 Aug 2026 18:00:34 -0400

CVE-2026-59886 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u
CVE-2026-59884 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating
CVE-2026-59885 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua

libgcrypt20 Sep 1st 17:07
Release: resolute Repo: universe Level: security New version: 1.12.0-2ubuntu1.1
Packages in group:  libgcrypt-bin libgcrypt-mingw-w64-dev

libgcrypt20 (1.12.0-2ubuntu1.1) resolute-security; urgency=medium

  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
    - debian/patches/CVE-2024-2236-1.patch: rsa: Do not accept invalid PKCS#1.5
      padding when deciphering in cipher/rsa-common.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-2.patch: rsa: Constant time blinding removal
      in cipher/rsa.c, configure.ac, mpi/Makefile.am, mpi/mpi-internal.h,
      mpi/mpi-mul-cs.c, mpi/mpi-mul.c, src/gcrypt-int.h.
    - debian/patches/CVE-2024-2236-3.patch: Constant time conversion of the
      message to the SEXP in cipher/rsa.c, src/const-time.c, src/const-time.h,
      src/sexp.c.
    - debian/patches/CVE-2024-2236-4.patch: rsa: Implement constant-time
      conversion of MPI to string in cipher/rsa-common.c.
    - debian/patches/CVE-2024-2236-5.patch: cipher: Use the constant time
      conversion also for OAEP in cipher/rsa-common.c, cipher/rsa.c.
    - debian/patches/CVE-2024-2236-6.patch: Implement implicit rejection for
      PKCS#1.5 decipher in cipher/pubkey-internal.h, cipher/pubkey-util.c,
      cipher/rsa-common.c, cipher/rsa.c, src/cipher.h, src/const-time.h,
      tests/pkcs1v2-v15c.h, tests/pkcs1v2.c.
    - debian/rules: build with --enable-marvin-workaround.
    - Thanks for Red Hat for the patches!
    - CVE-2024-2236

 -- Marc Deslauriers Mon, 24 Aug 2026 13:54:07 -0400

CVE-2024-2236 A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty

pam Sep 1st 17:07
Release: resolute Repo: main Level: security New version: 1.7.0-5ubuntu3.2
Packages in group:  libpam0g libpam0g-dev libpam-doc libpam-modules libpam-modules-bin libpam-runtime

pam (1.7.0-5ubuntu3.2) resolute-security; urgency=medium

  * SECURITY UPDATE: account lockout bypass in pam_faillock account
    management phase (LP: #2164901)
    - debian/patches/lp-2164901.patch: skip clearing user's failed
      attempt in modules/pam_faillock/pam_faillock.8.xml,
      modules/pam_faillock/pam_faillock.c.
    - No CVE number

 -- Shafayat Hossain Majumder Wed, 26 Aug 2026 15:28:39 -0400

2164901 pam_faillock lockout silently defeated by cron/systemd-user account-phase calls - Ubuntu pam 1.7.0-5ubuntu3.1 predates upstream fix

libgcrypt20 Sep 1st 17:07
Release: resolute Repo: main Level: security New version: 1.12.0-2ubuntu1.1
Packages in group:  libgcrypt20-dev libgcrypt20-doc

libgcrypt20 (1.12.0-2ubuntu1.1) resolute-security; urgency=medium

  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
    - debian/patches/CVE-2024-2236-1.patch: rsa: Do not accept invalid PKCS#1.5
      padding when deciphering in cipher/rsa-common.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-2.patch: rsa: Constant time blinding removal
      in cipher/rsa.c, configure.ac, mpi/Makefile.am, mpi/mpi-internal.h,
      mpi/mpi-mul-cs.c, mpi/mpi-mul.c, src/gcrypt-int.h.
    - debian/patches/CVE-2024-2236-3.patch: Constant time conversion of the
      message to the SEXP in cipher/rsa.c, src/const-time.c, src/const-time.h,
      src/sexp.c.
    - debian/patches/CVE-2024-2236-4.patch: rsa: Implement constant-time
      conversion of MPI to string in cipher/rsa-common.c.
    - debian/patches/CVE-2024-2236-5.patch: cipher: Use the constant time
      conversion also for OAEP in cipher/rsa-common.c, cipher/rsa.c.
    - debian/patches/CVE-2024-2236-6.patch: Implement implicit rejection for
      PKCS#1.5 decipher in cipher/pubkey-internal.h, cipher/pubkey-util.c,
      cipher/rsa-common.c, cipher/rsa.c, src/cipher.h, src/const-time.h,
      tests/pkcs1v2-v15c.h, tests/pkcs1v2.c.
    - debian/rules: build with --enable-marvin-workaround.
    - Thanks for Red Hat for the patches!
    - CVE-2024-2236

 -- Marc Deslauriers Mon, 24 Aug 2026 13:54:07 -0400

CVE-2024-2236 A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty

libgcrypt20 Sep 1st 17:07
Release: noble Repo: universe Level: security New version: 1.10.3-2ubuntu0.2
Packages in group:  libgcrypt-mingw-w64-dev

libgcrypt20 (1.10.3-2ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
    - debian/patches/CVE-2024-2236-1.patch: rsa: Do not accept invalid PKCS#1.5
      padding when deciphering in cipher/rsa-common.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-2.patch: rsa: Constant time blinding removal
      in cipher/rsa.c, configure.ac, mpi/Makefile.am, mpi/mpi-internal.h,
      mpi/mpi-mul-cs.c, mpi/mpi-mul.c, src/gcrypt-int.h.
    - debian/patches/CVE-2024-2236-3.patch: Constant time conversion of the
      message to the SEXP in cipher/rsa.c, src/const-time.c, src/const-time.h,
      src/sexp.c.
    - debian/patches/CVE-2024-2236-4.patch: rsa: Implement constant-time
      conversion of MPI to string in cipher/rsa-common.c.
    - debian/patches/CVE-2024-2236-5.patch: cipher: Use the constant time
      conversion also for OAEP in cipher/rsa-common.c, cipher/rsa.c.
    - debian/patches/CVE-2024-2236-6.patch: Implement implicit rejection for
      PKCS#1.5 decipher in cipher/pubkey-internal.h, cipher/pubkey-util.c,
      cipher/rsa-common.c, cipher/rsa.c, src/cipher.h, src/const-time.c,
      src/const-time.h, tests/pkcs1v2-v15c.h, tests/pkcs1v2.c.
    - debian/rules: build with --enable-marvin-workaround.
    - Thanks for Red Hat for the patches!
    - CVE-2024-2236

 -- Marc Deslauriers Mon, 24 Aug 2026 14:06:29 -0400

CVE-2024-2236 A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty

libgcrypt20 Sep 1st 17:07
Release: noble Repo: main Level: security New version: 1.10.3-2ubuntu0.2
Packages in group:  libgcrypt20-dev libgcrypt20-doc

libgcrypt20 (1.10.3-2ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
    - debian/patches/CVE-2024-2236-1.patch: rsa: Do not accept invalid PKCS#1.5
      padding when deciphering in cipher/rsa-common.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-2.patch: rsa: Constant time blinding removal
      in cipher/rsa.c, configure.ac, mpi/Makefile.am, mpi/mpi-internal.h,
      mpi/mpi-mul-cs.c, mpi/mpi-mul.c, src/gcrypt-int.h.
    - debian/patches/CVE-2024-2236-3.patch: Constant time conversion of the
      message to the SEXP in cipher/rsa.c, src/const-time.c, src/const-time.h,
      src/sexp.c.
    - debian/patches/CVE-2024-2236-4.patch: rsa: Implement constant-time
      conversion of MPI to string in cipher/rsa-common.c.
    - debian/patches/CVE-2024-2236-5.patch: cipher: Use the constant time
      conversion also for OAEP in cipher/rsa-common.c, cipher/rsa.c.
    - debian/patches/CVE-2024-2236-6.patch: Implement implicit rejection for
      PKCS#1.5 decipher in cipher/pubkey-internal.h, cipher/pubkey-util.c,
      cipher/rsa-common.c, cipher/rsa.c, src/cipher.h, src/const-time.c,
      src/const-time.h, tests/pkcs1v2-v15c.h, tests/pkcs1v2.c.
    - debian/rules: build with --enable-marvin-workaround.
    - Thanks for Red Hat for the patches!
    - CVE-2024-2236

 -- Marc Deslauriers Mon, 24 Aug 2026 14:06:29 -0400

CVE-2024-2236 A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty

libgcrypt20 Sep 1st 17:07
Release: jammy Repo: universe Level: security New version: 1.9.4-3ubuntu3.3
Packages in group:  libgcrypt-mingw-w64-dev

libgcrypt20 (1.9.4-3ubuntu3.3) jammy-security; urgency=medium

  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation
    - debian/patches/CVE-2024-2236-pre01.patch: rsa: Fix decoding of PKCS#1 v1.5
      and OAEP padding. in cipher/rsa-common.c, cipher/rsa.c, src/Makefile.am,
      src/const-time.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-pre02.patch: const-time: Use ct_not_memequal,
      instead. Tested with AVR. in cipher/rsa-common.c, src/const-time.c,
      src/const-time.h.
    - debian/patches/CVE-2024-2236-pre03.patch: const-time: always avoid
      comparison operator for byte comparison in src/const-time.h.
    - debian/patches/CVE-2024-2236-pre04.patch: const-time: Add ct_memmov_cond,
      fix _gcry_mpih_set_cond. in mpi/mpih-const-time.c, src/const-time.c,
      src/const-time.h.
    - debian/patches/CVE-2024-2236-pre05.patch: Use single constant-time memory
      comparison implementation in cipher/bufhelp.h, src/const-time.c,
      src/const-time.h.
    - debian/patches/CVE-2024-2236-pre06.patch: cipher: Fix ElGamal decryption.
      in cipher/elgamal.c, cipher/rsa.c.
    - debian/patches/CVE-2024-2236-pre07.patch: rsa, elgamal: avoid logical not
      operator in constant-time code in cipher/elgamal.c, cipher/rsa-common.c,
      cipher/rsa.c, src/const-time.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-pre08.patch: rsa: Use memmov_independently
      when unpadding. in cipher/rsa-common.c.
    - debian/patches/CVE-2024-2236-pre09.patch: const-time: prefix global
      symbols with _gcry_ in src/const-time.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-pre10.patch: const-time: ct_memmov_cond:
      switch to use dual mask approach in src/const-time.c.
    - debian/patches/CVE-2024-2236-pre11.patch: mpih_set_cond: restore EM
      leakage mitigation in mpi/mpih-const-time.c.
    - debian/patches/CVE-2024-2236-pre12.patch: mpih-const-time: use global
      vzero/vone variable in mpi/mpih-const-time.c.
    - debian/patches/CVE-2024-2236-pre13.patch: mpih_cmp_ui: avoid unintentional
      conditional branch in mpi/mpi-internal.h, mpi/mpih-const-time.c.
    - debian/patches/CVE-2024-2236-pre14.patch: mpiutil: use global vone and
      vzero in mpi/mpiutil.c.
    - debian/patches/CVE-2024-2236-pre15.patch: const-time: add functions for
      generating masks from 0/1 input in mpi/mpi-internal.h, mpi/mpih-const-
      time.c, mpi/mpiutil.c, src/const-time.c, src/const-time.h.
    - debian/patches/CVE-2024-2236-pre16.patch: mpih-const-time: use constant-
      time comparisons conditional add/sub/abs in mpi/mpih-const-time.c.
    - debian/patches/CVE-2024-2236-pre17.patch: mpih_mod: avoid unintentional
      conditional branch in mpi/mpih-const-time.c.
    - debian/patches/CVE-2024-2236-pre18.patch: mpi: Fix for 64-bit for
      _gcry_mpih_cmp_ui. in mpi/mpih-const-time.c.
    - debian/patches/CVE-2024-2236-pre19.patch: addm/subm/mulm: fix case when
      destination is same MPI as divide

(See more...)
CVE-2024-2236 A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-sty



About   -   Send Feedback to @ubuntu_updates