Back

MEDIUM

Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack

Published Jun 19, 2019

Description

In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack

Affected products

Remediation

Red Hat statement

Please note that this issue is more theoretical than practical in terms of potential attack scenarios. The upstream developers have disputed this CVE, and the patches they supplied seem to focus more on hardening. Refer to external references for further details.

Weaknesses (2)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 19, 2019
Updated Aug 4, 2024
Reserved Jun 19, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 16, 2019
ENISA EUVD
Assigner mitre
Published Jun 19, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-4482