{"id":"SUSE-SU-2024:2298-1","summary":"Security update for openCryptoki","details":"This update for openCryptoki fixes the following issues:\n\nopenCryptoki was updated to version to 3.17.0 (bsc#1220266, bsc#1219217)\n\n+ openCryptoki 3.17\n\n - tools: added function to list keys to p11sak\n - common: added support for OpenSSL 3.0\n - common: added support for event notifications\n - ICA: added SW fallbacks\n\n+ openCryptoki 3.16\n\n - EP11: protected-key option\n - EP11: support attribute-bound keys\n - CCA: import and export of secure key objects\n - Bug fixes\n\n+ openCryptoki 3.15.1\n\n - Bug fixes\n\n+ openCryptoki 3.15\n\n - common: conform to PKCS 11 3.0 Baseline Provider profile\n - Introduce new vendor defined interface named 'Vendor IBM'\n - Support C_IBM_ReencryptSingle via 'Vendor IBM' interface\n - CCA: support key wrapping\n - SOFT: support ECC\n - p11sak tool: add remove-key command\n - Bug fixes\n\n+ openCryptoki 3.14\n\n - EP11: Dilitium support stage 2\n - Common: Rework on process and thread locking\n - Common: Rework on btree and object locking\n - ICSF: minor fixes\n - TPM, ICA, ICSF: support multiple token instances\n - new tool p11sak\n\n+ openCryptoki 3.13.0\n\n - EP11: Dilithium support\n - EP11: EdDSA support\n - EP11: support RSA-OAEP with non-SHA1 hash and MGF\n\n+ openCryptoki 3.12.1\n\n - Fix pkcsep11_migrate tool\n\n+ openCryptoki 3.12.0\n\n - Update token pin and data store encryption for soft,ica,cca and ep11\n - EP11: Allow importing of compressed EC public keys\n - EP11: Add support for the CMAC mechanisms\n - EP11: Add support for the IBM-SHA3 mechanisms\n - SOFT: Add AES-CMAC and 3DES-CMAC support to the soft token\n - ICA: Add AES-CMAC and 3DES-CMAC support to the ICA token\n - EP11: Add config option USE_PRANDOM\n - CCA: Use Random Number Generate Long for token_specific_rng()\n - Common rng function: Prefer /dev/prandom over /dev/urandom\n - ICA: add SHA*_RSA_PKCS_PSS mechanisms\n - Bug fixes  \n","modified":"2026-03-11T07:27:01.561534Z","published":"2024-07-04T07:08:40Z","related":["CVE-2024-0914"],"upstream":["CVE-2024-0914"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20242298-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1219217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1220266"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-0914"}],"affected":[{"package":{"name":"openCryptoki","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.17.0-5.9.2"}]}],"ecosystem_specific":{"binaries":[{"openCryptoki-devel":"3.17.0-5.9.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2298-1.json"}},{"package":{"name":"openCryptoki","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.17.0-5.9.2"}]}],"ecosystem_specific":{"binaries":[{"openCryptoki-32bit":"3.17.0-5.9.2","openCryptoki-64bit":"3.17.0-5.9.2","openCryptoki":"3.17.0-5.9.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2298-1.json"}},{"package":{"name":"openCryptoki","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.17.0-5.9.2"}]}],"ecosystem_specific":{"binaries":[{"openCryptoki-32bit":"3.17.0-5.9.2","openCryptoki-64bit":"3.17.0-5.9.2","openCryptoki":"3.17.0-5.9.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2298-1.json"}}],"schema_version":"1.7.5"}