Name | CVE-2024-45191 |
Description | An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 1079487 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
olm (PTS) | buster | 2.2.2+git20170526.0fd768e+dfsg-1 | vulnerable |
| bullseye | 3.2.1~dfsg-7 | vulnerable |
| bookworm | 3.2.13~dfsg-1 | vulnerable |
| sid, trixie | 3.2.16+dfsg-3 | vulnerable |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
olm | source | buster | (unfixed) | end-of-life | | |
olm | source | (unstable) | (unfixed) | | | 1079487 |
Notes
[bookworm] - olm <ignored> (Minor issue, libolm is deprecated and won't be fixed)
[bullseye] - olm <ignored> (Minor issue; libolm deprecated upstream)
https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/
libolm is deprecated upstream:
https://gitlab.matrix.org/matrix-org/olm/-/commit/6d4b5b07887821a95b144091c8497d09d377f985
https://matrix.org/blog/2024/08/libolm-deprecation/