Rust-openssl: timing based side-channel can lead to a bleichenbacher style attack
Published Apr 4, 2024
5.9
MEDIUMCVSS 3.1
EPSS 0.41%
Description
A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages for decryption. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 8
389-ds:1.4/389-ds-base
Not affected
Red Hat Enterprise Linux 8
python3.12-cryptography
Not affected
Red Hat Enterprise Linux 9
389-ds-base
Not affected
Red Hat Enterprise Linux 9
keylime-agent-rust
Not affected
Red Hat Enterprise Linux 9
python3.12-cryptography
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.12-cryptography | Not affected | n/a |
| Red Hat Enterprise Linux 9 | 389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 9 | keylime-agent-rust | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.12-cryptography | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
The Red Hat Enterprise Linux remains unaffected by this vulnerability since it does not include the vulnerable codebase or version.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (4)
- https://access.redhat.com/security/cve/CVE-2024-3296 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2269723 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2024-3296
- https://www.cve.org/CVERecord?id=CVE-2024-3296
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-3296 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2269723 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-3296 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-3296 |
Change history (0)
No recorded changes yet.