漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)
Vulnerability Description
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber
Vulnerability Type
通过时间差异性导致的信息暴露
Vulnerability Title
Bouncy Castle for Java 侧信道信息泄露漏洞
Vulnerability Description
Bouncy Castle Bouncy Castle for Java是Bouncy Castle组织的一个加密库。 Bouncy Castle for Java 1.73版本至1.78之前版本存在侧信道信息泄露漏洞,该漏洞源于ML-KEM例程中Poly.toMsg、Poly.compressPoly和PolyVec.compressPolyVec函数除以模数q产生时序差异,攻击者可通过测量大量解密操作的时序恢复私钥。
CVSS Information
N/A
Vulnerability Type
N/A