Memory Management Bugs Fixed in OpenSSL and GnuTLS

February 13, 2023

At the same time, a similar bug was reported in GnuTLS, identified as CVE-2023-0361. This bug appeared in code that was supposed to log timing attack errors in the first place, and was caused by the code taking different amounts of time depending on which way the code went after a “branch” instruction. Both of these bugs have now been fixed, ensuring that the security of OpenSSL and GnuTLS is maintained.

