Описание
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
A flaw was found in Bouncy Castle for Java, affecting ML-KEM (CRYSTALS-Kyber) routines. Specifically, the Poly.toMsg, Poly.compressPoly, and PolyVec.compressPolyVec routines, which handle secret-derived polynomial coefficients, perform division by the modulus q. A remote attacker can exploit this timing side-channel vulnerability by measuring the time taken for a large number of decapsulations using the same long-term private key. Successful exploitation allows the attacker to recover the long-term private key, leading to a significant compromise of cryptographic security.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | bcprov-jdk18on | Not affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Not affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Not affected | ||
| Red Hat AMQ Broker 7 | bcprov-jdk18on | Not affected | ||
| Red Hat AMQ Clients | bcprov-jdk15on | Not affected | ||
| Red Hat AMQ Clients | bcprov-jdk18on | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/de-minimal-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/de-supported-rhel9 | Not affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | bcprov-jdk18on | Not affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | bcprov-jdk18on | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYS ...
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
5.9 Medium
CVSS3