Assigner | redhat |
Reserved | 2023-11-21 |
Published | 2024-02-04 |
Updated | 2024-06-05 |
Description
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N |
Problem types
Product status
0:4.18.0-553.5.1.rt7.346.el8_10 before *
0:4.18.0-553.5.1.el8_10 before *
0:5.14.0-427.16.1.el9_4 before *
0:5.14.0-427.16.1.el9_4 before *
0:5.14.0-70.101.1.el9_0 before *
0:5.14.0-70.101.1.rt21.173.el9_0 before *
0:5.14.0-284.62.1.el9_2 before *
0:5.14.0-284.62.1.rt14.347.el9_2 before *
Timeline
2023-11-21: | Reported to Red Hat. |
2023-09-25: | Made public. |
References
https://access.redhat.com/errata/RHSA-2024:1881 (RHSA-2024:1881)
https://access.redhat.com/errata/RHSA-2024:1882 (RHSA-2024:1882)
https://access.redhat.com/errata/RHSA-2024:2758 (RHSA-2024:2758)
https://access.redhat.com/errata/RHSA-2024:3414 (RHSA-2024:3414)
https://access.redhat.com/errata/RHSA-2024:3421 (RHSA-2024:3421)
https://access.redhat.com/errata/RHSA-2024:3618 (RHSA-2024:3618)
https://access.redhat.com/errata/RHSA-2024:3627 (RHSA-2024:3627)
https://access.redhat.com/security/cve/CVE-2023-6240
https://bugzilla.redhat.com/show_bug.cgi?id=2250843 (RHBZ#2250843)
https://people.redhat.com/~hkario/marvin/
https://securitypitfalls.wordpress.com/2023/10/16/experiment-with-side-channel-attacks-yourself/
https://security.netapp.com/advisory/ntap-20240628-0002/