CVE-2024-28834: Red Hat Enterprise Linux 10
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 0:3.6.16-8.el8_9.3 (fixed in 0:3.6.16-8.el8_9.3)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support: before 0:3.6.16-5.el8_6.4 (fixed in 0:3.6.16-5.el8_6.4)
- Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 0:3.6.16-7.el8_8.3 (fixed in 0:3.6.16-7.el8_8.3)
- Red Hat Red Hat Enterprise Linux 9: before 0:3.7.6-23.el9_3.4 (fixed in 0:3.7.6-23.el9_3.4); before 0:3.8.3-4.el9_4 (fixed in 0:3.8.3-4.el9_4)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:3.7.6-21.el9_2.3 (fixed in 0:3.7.6-21.el9_2.3)
Published 2024-03-21. Last modified 2026-06-17.