Bouncy Castle Bouncy Castle for Java是Bouncy Castle组织的一个加密库。 Bouncy Castle for Java 1.73版本至1.78之前版本存在侧信道信息泄露漏洞,该漏洞源于ML-KEM例程中Poly.toMsg、Poly.compressPoly和PolyVec.compressPolyVec函数除以模数q产生时序差异,攻击者可通过测量大量解密操作的时序恢复私钥。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.73< 1.78 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.73 ~ 1.78 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet