[Bug 1209627] New: jitterentropy: Stack corruption on s390x architecture
https://bugzilla.suse.com/show_bug.cgi?id=1209627 Bug ID: 1209627 Summary: jitterentropy: Stack corruption on s390x architecture Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: pmonrealgonzalez@suse.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- We have seen a couple of projects failing to build recently due to a stack corruption in the jitterentropy-base-user.h:jent_get_nstime() function. We have seen the *** stack smashing detected *** when calculating the fipshmac in openssl-1_1 or gnutls when including the jitterentropy 140-3 FIPS patches. There is a patch merged upstream that fixes the issue, see: * https://github.com/smuellerDD/jitterentropy-library/pull/95 * https://github.com/smuellerDD/jitterentropy-library/commit/7bf9f85 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1209627 Pedro Monreal Gonzalez <pmonrealgonzalez@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |otto.hollmann@suse.com, | |pmonrealgonzalez@suse.com Assignee|security-team@suse.de |meissner@suse.com -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1209627 https://bugzilla.suse.com/show_bug.cgi?id=1209627#c1 Pedro Monreal Gonzalez <pmonrealgonzalez@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS --- Comment #1 from Pedro Monreal Gonzalez <pmonrealgonzalez@suse.com> --- Fix submitted here: https://build.opensuse.org/request/show/1073856 This doesn't seem to affect SLE-15-SP4. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com