Wind River Support Network

HomeDefectsLIN10-4595
Not to be fixed

LIN10-4595 : Security Advisory - gnutls - CVE-2018-10846

Created: Aug 30, 2018    Updated: Dec 22, 2022
Resolved Date: Dec 22, 2022
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of Just in Time Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

https://nvd.nist.gov/vuln/detail/CVE-2018-10846

CVEs


Live chat
Online