{"id":"SUSE-SU-2023:4060-1","summary":"Security update for rage-encryption","details":"This update for rage-encryption fixes the following issues:\n\n -CVE-2023-42811: chosen ciphertext attack possible against aes-gcm (bsc#1215657)\n\n  * update vendor.tar.zst to contain aes-gcm \u003e= 0.10.3\n\n- Update to version 0.9.2+0:\n\n  * CI: Ensure `apt` repository is up-to-date before installing build deps\n  * CI: Build Linux releases using `ubuntu-20.04` runner\n  * CI: Remove most uses of `actions-rs` actions\n\n- Update to version 0.9.2+0:\n\n  * Fix changelog bugs and add missing entry\n  * Document `PINENTRY_PROGRAM` environment variable\n  * age: Add `Decryptor::new_async_buffered`\n  * age: `impl AsyncBufRead for ArmoredReader`\n  * Pre-initialize vectors when the capacity is known, or use arrays\n  * Use `PINENTRY_PROGRAM` as environment variable for `pinentry`\n  * Document why `impl AsyncWrite for StreamWriter` doesn't loop indefinitely\n  * cargo update\n  * cargo vet prune\n  * Migrate to `cargo-vet 0.7`\n  * build(deps): bump svenstaro/upload-release-action from 2.5.0 to 2.6.1\n  * Correct spelling in documentation\n  * build(deps): bump codecov/codecov-action from 3.1.1 to 3.1.4\n  * StreamWriter AsyncWrite: fix usage with futures::io::copy()\n  * rage: Use `Decryptor::new_buffered`\n  * age: Add `Decryptor::new_buffered`\n  * age: `impl BufRead for ArmoredReader`\n  * Update Homebrew formula to v0.9.1\n  * feat/pinentry: Use env var to define pinentry binary\n\n- Update to version 0.9.1+0:\n\n  * ssh: Fix parsing of OpenSSH private key format\n  * ssh: Support `aes256-gcm@openssh.com` ciphers for encrypted keys\n  * ssh: Add `aes256-gcm@openssh.com` cipher to test cases\n  * ssh: Extract common key material derivation logic for encrypted keys\n  * ssh: Use associated constants for key and IV sizes\n  * ssh: Add test cases for encrypted keys\n- Add shell completions for fish and zsh.\n","modified":"2026-03-11T07:24:57.026467Z","published":"2023-10-12T08:05:57Z","related":["CVE-2023-42811"],"upstream":["CVE-2023-42811"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234060-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215657"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42811"}],"affected":[{"package":{"name":"rage-encryption","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/rage-encryption&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.2+0-150500.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"rage-encryption":"0.9.2+0-150500.3.3.1","rage-encryption-bash-completion":"0.9.2+0-150500.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4060-1.json"}},{"package":{"name":"rage-encryption","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/rage-encryption&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.2+0-150500.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"rage-encryption-bash-completion":"0.9.2+0-150500.3.3.1","rage-encryption":"0.9.2+0-150500.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4060-1.json"}}],"schema_version":"1.7.5"}