Timing Vulnerability in Bouncy Castle for Java Affecting Key Management Functions
CVE-2024-14041

8.2HIGH

What is CVE-2024-14041?

A timing vulnerability exists in Bouncy Castle for Java versions 1.73 to 1.77, where specific routines related to the ML-KEM (CRYSTALS-Kyber) cryptographic framework could allow an attacker to exploit timing discrepancies during the execution of decapsulation. By measuring the time taken for decryption operations involving the same long-term private key, an attacker may be able to recover the private key, thus compromising the cryptographic integrity of the affected application. The impacted routines include Poly.toMsg and the ciphertext compression methods Poly.compressPoly and PolyVec.compressPolyVec, while encapsulation remains unaffected. Implementing recommended patches is crucial to mitigate this vulnerability.

Affected Version(s)

BC-JAVA all 1.73 < 1.78

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Robusta team: Deepak Pillai, Anirban Chakraborty, Chitchanok Chuengsatiansup, Matthew Roughan, Peter Schwabe and Yuval Yarom
The KyberSlash authors: Daniel J. Bernstein, Karthikeyan Bhargavan, Shivam Bhasin, Anupam Chattopadhyay, Tee Kiah Chia, Matthias J. Kannwischer, Franziskus Kiefer, Thales Paiva, Prasanna Ravi and Goutam Tamvada.
.