Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9763-4f94-gfch

Опубликовано: 08 янв. 2024
Источник: github
Github: Прошло ревью

Описание

CIRCL's Kyber: timing side-channel (kyberslash2)

Impact

On some platforms, when an attacker can time decapsulation of Kyber on forged cipher texts, they could possibly learn (parts of) the secret key.

Does not apply to ephemeral usage, such as when used in the regular way in TLS.

Patches

Patched in 1.3.7.

References

Пакеты

Наименование

github.com/cloudflare/circl

go
Затронутые версииВерсия исправления

< 1.3.7

1.3.7