CVE-2024-2236

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

  • Published Mar 6, 2024
  • CVSS 5.9 medium
  • 1.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2024-2236 at the National Vulnerability Database