Bug 32904 - opensc new security issue CVE-2023-5992
Summary: opensc new security issue CVE-2023-5992
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-02-27 13:00 CET by Nicolas Salguero
Modified: 2024-03-31 05:29 CEST (History)
3 users (show)

See Also:
Source RPM: opensc-0.22.0-3.mga9.src.rpm
CVE: CVE-2023-5992
Status comment:


Attachments

Description Nicolas Salguero 2024-02-27 13:00:40 CET
RedHat has issued an advisory on February 26:
https://lwn.net/Articles/963644/

Mageia 9 is also affected.
Nicolas Salguero 2024-02-27 13:02:19 CET

Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2023-5992
Status comment: (none) => Fixed upstream in 0.25.0
Source RPM: (none) => opensc-0.22.0-3.mga9.src.rpm

Comment 1 Nicolas Salguero 2024-02-27 13:03:31 CET
Another reference:
https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992

The following pull request fixes the issue:
https://github.com/OpenSC/OpenSC/pull/2948
Comment 2 Lewis Smith 2024-02-27 20:36:12 CET
No one obvious packager for this, so assigning the security update globally.

Assignee: bugsquad => pkg-bugs

Nicolas Salguero 2024-03-19 14:36:03 CET

Version: Cauldron => 9
Whiteboard: MGA9TOO => (none)

Comment 3 Nicolas Salguero 2024-03-22 14:07:28 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Side-channel leaks while stripping encryption PKCS#1.5 padding in OpenSC. (CVE-2023-5992)

References:
https://lwn.net/Articles/963644/
https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992
========================

Updated packages in core/updates_testing:
========================
lib(64)opensc11-0.25.0-1.mga9
lib(64)opensc-devel-0.25.0-1.mga9
lib(64)smm-local11-0.25.0-1.mga9
opensc-0.25.0-1.mga9

from SRPM:
opensc-0.25.0-1.mga9.src.rpm

Status comment: Fixed upstream in 0.25.0 => (none)
Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs

Comment 4 Herman Viaene 2024-03-23 14:29:36 CET
MGA9-64 Plasma Wayland on HP-Pavillion
No installation issues, installed Belgian eid software as well.
Running eidenv command from opensc:
$ eidenv 
Using reader with a card: VASCO DIGIPASS 870 [CCID] 00 00
BELPIC_CARDNUMBER: xxxxxxxx
BELPIC_CHIPNUMBER: yyyyyyyyyyyyyyyyyyyyyyy
etc.......
Running Belgian eid-viewer displays data and picture from eid-card correctly.
Added Belgium eid extension to Firefox and configured its security device, then I could login into government site demanding authentication via eid-card.
All works OK.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

Comment 5 Thomas Andrews 2024-03-24 01:19:01 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

katnatek 2024-03-29 21:34:30 CET

Keywords: (none) => advisory

Comment 6 Mageia Robot 2024-03-31 05:29:14 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0101.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.