CVE-2024-14041

EUVD-2024-55702
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 27.61%
Affected Products (NVD)
VendorProductVersion
bouncycastlebc-java
1.73 ≤
𝑥
< 1.78
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bouncycastle
bookworm
vulnerable
bullseye
vulnerable
forky
1.80-3
fixed
sid
1.80-3
fixed
trixie
1.80-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bouncycastle
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
not-affected