Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-14041

Опубликовано: 28 июл. 2026
Источник: redhat
CVSS3: 5.9

Описание

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.

A flaw was found in Bouncy Castle for Java, affecting ML-KEM (CRYSTALS-Kyber) routines. Specifically, the Poly.toMsg, Poly.compressPoly, and PolyVec.compressPolyVec routines, which handle secret-derived polynomial coefficients, perform division by the modulus q. A remote attacker can exploit this timing side-channel vulnerability by measuring the time taken for a large number of decapsulations using the same long-term private key. Successful exploitation allows the attacker to recover the long-term private key, leading to a significant compromise of cryptographic security.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4bcprov-jdk18onNot affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Not affected
Red Hat AMQ Broker 7bcprov-jdk18onNot affected
Red Hat AMQ Clientsbcprov-jdk15onNot affected
Red Hat AMQ Clientsbcprov-jdk18onNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/de-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/de-supported-rhel9Not affected
Red Hat build of Apache Camel 4 for Quarkus 3bcprov-jdk18onNot affected
Red Hat build of Apache Camel for Spring Boot 4bcprov-jdk18onNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2507933bouncycastle: Bouncy Castle for Java: Private key recovery via timing side-channel in ML-KEM (CRYSTALS-Kyber) routines

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 1 месяца назад

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.

CVSS3: 5.9
nvd
около 1 месяца назад

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.

CVSS3: 5.9
debian
около 1 месяца назад

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYS ...

CVSS3: 5.9
github
около 1 месяца назад

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.

5.9 Medium

CVSS3