Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS05NzYzLTRmOTQtZ2ZjaM4AA4Ql

CIRCL's Kyber: timing side-channel (kyberslash2)

Impact

On some platforms, when an attacker can time decapsulation of Kyber on forged cipher texts, they could possibly learn (parts of) the secret key.

Does not apply to ephemeral usage, such as when used in the regular way in TLS.

Patches

Patched in 1.3.7.

References

Permalink: https://github.com/advisories/GHSA-9763-4f94-gfch
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05NzYzLTRmOTQtZ2ZjaM4AA4Ql
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 11 months ago
Updated: 7 months ago


Identifiers: GHSA-9763-4f94-gfch
References: Repository: https://github.com/cloudflare/circl
Blast Radius: 0.0

Affected Packages

go:github.com/cloudflare/circl
Dependent packages: 6,861
Dependent repositories: 2,787
Downloads:
Affected Version Ranges: < 1.3.7
Fixed in: 1.3.7
All affected versions: 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6
All unaffected versions: 1.3.7, 1.3.8, 1.3.9, 1.4.0, 1.5.0