Bug 30957 - openssl new security issues CVE-2022-3358, CVE-2022-3602, and CVE-2022-3786
Summary: openssl new security issues CVE-2022-3358, CVE-2022-3602, and CVE-2022-3786
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Salguero
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-10-12 02:08 CEST by David Walser
Modified: 2022-11-01 22:36 CET (History)
0 users

See Also:
Source RPM: openssl-3.0.5-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-10-12 02:08:26 CEST
OpenSSL has issued an advisory today (October 11):
https://www.openssl.org/news/secadv/20221011.txt

The issue is fixed upstream in 3.0.6.

The update is committed in SVN for Cauldron, but has a test failure:
http://pkgsubmit.mageia.org/uploads/failure/cauldron/core/release/20221011211008.luigiwalser.duvel.3785240/log/openssl-3.0.6-1.mga9/build.aarch64.0.20221011215711.log
David Walser 2022-10-12 02:08:48 CEST

Status comment: (none) => Committed in SVN, has a test suite failure

Comment 1 Lewis Smith 2022-10-13 21:33:54 CEST
Assigning to NicolasS as you have several CVE updates to openssl to your credit.

Assignee: bugsquad => nicolas.salguero

Comment 2 David Walser 2022-10-26 18:45:11 CEST
3.0.7 will be released on November 1 with a critical security fix:
https://www.openwall.com/lists/oss-security/2022/10/25/4

It appears that 1.1.1 isn't affected.  Hopefully this will also fix the test suite.
Comment 3 David Walser 2022-11-01 17:43:07 CET
OpenSSL has issued an advisory today (November 1):
https://www.openssl.org/news/secadv/20221101.txt

The issues are fixed upstream in 3.0.7.

Status comment: Committed in SVN, has a test suite failure => Fixed upstream in 3.0.7
Summary: openssl new security issue CVE-2022-3358 => openssl new security issues CVE-2022-3358, CVE-2022-3602, and CVE-2022-3786

Comment 4 David Walser 2022-11-01 21:06:06 CET
The update is committed in SVN for Cauldron, but has a test failure:
http://pkgsubmit.mageia.org/uploads/failure/cauldron/core/release/20221101194220.luigiwalser.duvel.3503556/log/openssl-3.0.7-1.mga9/build.aarch64.0.20221101194314.log

Status comment: Fixed upstream in 3.0.7 => Committed in SVN, has a test suite failure

Comment 5 David Walser 2022-11-01 22:36:52 CET
Fixed for now by reverting to 3.0.5 and adding patches for the CVEs.  We should fix the failing test (or probably report it upstream) so we will be able to update it later.  We don't want to spend Mageia 9's whole lifetime patching it.

Resolution: (none) => FIXED
Status comment: Committed in SVN, has a test suite failure => (none)
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.