Back

MEDIUM

libgcrypt: Possible timing attack on EdDSA session key

Published Jun 11, 2017

Description

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of libgcrypt as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include support for EdDSA cipher.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 11, 2017
Updated Aug 5, 2024
Reserved Jun 10, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 1, 2017