Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack
Published Jun 19, 2019
5.9
MEDIUMCVSS 3.1
EPSS 2.06%
Description
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
libgcrypt
Will not fix
Red Hat Enterprise Linux 6
libgcrypt
Will not fix
Red Hat Enterprise Linux 7
libgcrypt
Will not fix
Red Hat Enterprise Linux 8
libgcrypt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libgcrypt | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libgcrypt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | libgcrypt | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | libgcrypt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Please note that this issue is more theoretical than practical in terms of potential attack scenarios. The upstream developers have disputed this CVE, and the patches they supplied seem to focus more on hardening. Refer to external references for further details.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-12904 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1730320 Issue Tracking
- https://dev.gnupg.org/T4541 x_refsource_MISCThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4482 Advisory
- https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020 x_refsource_MISCPatchThird Party Advisory
- https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762 x_refsource_MISCPatchThird Party Advisory
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.gnupg.org/pipermail/gcrypt-devel/2019-July/004760.html
- https://nvd.nist.gov/vuln/detail/CVE-2019-12904
- https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12904.html
- https://www.cve.org/CVERecord?id=CVE-2019-12904
Change history (0)
No recorded changes yet.