MGASA-2025-0295

Source
https://advisories.mageia.org/MGASA-2025-0295.html
Import Source
https://advisories.mageia.org/MGASA-2025-0295.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2025-0295
Related
Published
2025-11-15T07:11:33Z
Modified
2025-11-15T06:22:06Z
Summary
Updated botan2 packages fix security vulnerabilitiy
Details

Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386 (only 32-bit processors can be affected). (CVE-2024-50383)

References
Credits

Affected packages

Mageia:9 / botan2

Package

Name
botan2
Purl
pkg:rpm/mageia/botan2?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.19.5-1.1.mga9

Ecosystem specific

{
    "section": "core"
}