#1079487 olm: CVE-2024-45191 CVE-2024-45192 CVE-2024-45193

Package:
src:olm
Source:
src:olm
Submitter:
Salvatore Bonaccorso
Date:
2024-08-31 00:36:02 UTC
Severity:
normal
Tags:
#1079487#5
Date:
2024-08-23 20:45:16 UTC
From:
To:
Hi,

The following vulnerabilities were published for olm.

CVE-2024-45191[0]:
| An issue was discovered in Matrix libolm (aka Olm) through 3.2.16.
| The AES implementation is vulnerable to cache-timing attacks due to
| use of S-boxes. This is related to software that uses a lookup table
| for the SubWord step. NOTE: This vulnerability only affects products
| that are no longer supported by the maintainer.


CVE-2024-45192[1]:
| An issue was discovered in Matrix libolm (aka Olm) through 3.2.16.
| Cache-timing attacks can occur due to use of base64 when decoding
| group session keys. NOTE: This vulnerability only affects products
| that are no longer supported by the maintainer.


CVE-2024-45193[2]:
| An issue was discovered in Matrix libolm (aka Olm) through 3.2.16.
| There is Ed25519 signature malleability due to lack of validation
| criteria (does not ensure that S < n). NOTE: This vulnerability only
| affects products that are no longer supported by the maintainer.

Note, that olm as beeing deprecated won't fix these issue, instead the
upstrem project commited:

https://gitlab.matrix.org/matrix-org/olm/-/commit/6d4b5b07887821a95b144091c8497d09d377f985

Should src:olm be removed from Debian (unstable)? There will be broken
reverse dependencies. Are they actually still usable for having in
Debian as well?

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-45191
https://www.cve.org/CVERecord?id=CVE-2024-45191
[1] https://security-tracker.debian.org/tracker/CVE-2024-45192
https://www.cve.org/CVERecord?id=CVE-2024-45192
[2] https://security-tracker.debian.org/tracker/CVE-2024-45193
https://www.cve.org/CVERecord?id=CVE-2024-45193

Regards,
Salvatore

#1079487#10
Date:
2024-08-30 23:53:58 UTC
From:
To:
severity 1079487 important

Thanks for filing this bug report.

(Full disclosure: I am employed by Element to work on Matrix software,
and am part of the cryptography team at Element.)

The Matrix.org foundation published a blog post about the
vulnerabilities and the libolm deprecation:
https://matrix.org/blog/2024/08/libolm-deprecation/ Of note: the blog
indicates that the vulnerabilities are not believed to be practically
exploitable, so:

On Fri, 23 Aug 2024 22:45:16 +0200, Salvatore Bonaccorso <carnil@debian.org> said:

...

I don't think that it needs to be removed.

Yes.  Nheko and NeoChat are Matrix clients that are still being actively
developed.  They may switch to vodozemac (the Rust implementation of the
Olm/Megolm protocols, that does not have these vulnerabilities) in the
future, but for now, libolm is still useful.

I've dropped the severity of this bug to "important" for now.  If the
security team disagrees, they can change the severity.