Skip to content

Commit

Permalink
Add CHANGES.md and NEWS.md updates for CVE-2024-13176
Browse files Browse the repository at this point in the history
Reviewed-by: Tim Hudson <tjh@openssl.org>
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Paul Dale <ppzgs1@gmail.com>
(Merged from openssl#26429)
  • Loading branch information
t8m committed Jan 20, 2025
1 parent 63c40a6 commit c3144e1
Show file tree
Hide file tree
Showing 2 changed files with 25 additions and 3 deletions.
14 changes: 14 additions & 0 deletions CHANGES.md
Original file line number Diff line number Diff line change
Expand Up @@ -127,6 +127,19 @@ OpenSSL 3.4

### Changes between 3.4.0 and 3.4.1 [xx XXX xxxx]

* Fixed timing side-channel in ECDSA signature computation.

There is a timing signal of around 300 nanoseconds when the top word of
the inverted ECDSA nonce value is zero. This can happen with significant
probability only for some of the supported elliptic curves. In particular
the NIST P-521 curve is affected. To be able to measure this leak, the
attacker process must either be located in the same physical computer or
must have a very fast network connection with low latency.

([CVE-2024-13176])

*Tomáš Mráz*

* Reverted the behavior change of CMS_get1_certs() and CMS_get1_crls()
that happened in the 3.4.0 release. These functions now return NULL
again if there are no certs or crls in the CMS object.
Expand Down Expand Up @@ -20986,6 +20999,7 @@ ndif

<!-- Links -->

[CVE-2024-13176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176
[CVE-2024-9143]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-9143
[CVE-2024-6119]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-6119
[CVE-2024-5535]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-5535
Expand Down
14 changes: 11 additions & 3 deletions NEWS.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,13 +49,20 @@ This release adds the following new features:
OpenSSL 3.4
-----------

### Major changes between OpenSSL 3.3 and OpenSSL 3.4 [under development]
### Major changes between OpenSSL 3.4.0 and OpenSSL 3.4.1 [under development]

This release is in development.

This release incorporates the following bug fixes and mitigations:

* Fixed timing side-channel in ECDSA signature computation.
([CVE-2024-13176])

### Major changes between OpenSSL 3.3 and OpenSSL 3.4.0 [22 Oct 2024]

OpenSSL 3.4.0 is a feature release adding significant new functionality to
OpenSSL.

This release is in development.

This release incorporates the following potentially significant or incompatible
changes:

Expand Down Expand Up @@ -1848,6 +1855,7 @@ OpenSSL 0.9.x

<!-- Links -->

[CVE-2024-13176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176
[CVE-2024-9143]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-9143
[CVE-2024-6119]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-6119
[CVE-2024-5535]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-5535
Expand Down

0 comments on commit c3144e1

Please sign in to comment.