Security Advisory

CVE-2024-0914

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-01-31 04:53:28
Last updated 2026-03-24 11:28:22
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.