Skip to content

Security Vulnerability: Alpine Linux 3.20, 3.21 - openssl Man-in-the-Middle Vulnerability - 3.3.3-r0 #364

@shwethadec01

Description

@shwethadec01

we have found security vulnerability w.r.t open-ssl for NVIDIA/Cuda, kindly have a look and provide the fix

Summary

Inclusion of vulnerable OpenSSL from Alpine base image

Details

TLS and DTLS connections using raw public keys may be vulnerable to man-in-middle attacks when server authentication failure is not detected by clients. RPKs are disabled by default in both TLS clients and TLS servers. Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set. [CVE-2024-12797] Vendor Affected Components: Alpine Linux: 3.20 Alpine Linux: 3.21.

Action Required

Upgrade the base Alpine image and ensure OpenSSL is patched.

CVEs:

CVE-2024-12797

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions