CVE-2023-5992: Opensc: side-channel leaks while stripping encryption pkcs#1 padding
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
Other sources
The OpenSC code handling the PKCS#1 encryption padding removal is not implemented in side-channel resistant way, which can lead to possible leak to private key data.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openscto a version that resolves this vulnerability.Fixed in 0.21.0-1+deb11u1Fixed in 0.23.0-0.3+deb12u2Fixed in 0.26.1-1 - Upgrade
Upgrade
redhat/OpenSCto a version that resolves this vulnerability.Fixed in 0.24.0
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5992?
The severity of CVE-2023-5992 is categorized as high due to the potential leak of private data through side-channel attacks.
How do I fix CVE-2023-5992?
To fix CVE-2023-5992, update OpenSC to version 0.24.0 or newer.
Which versions of OpenSC are affected by CVE-2023-5992?
OpenSC versions below 0.25.0 are affected by CVE-2023-5992.
What types of systems are vulnerable to CVE-2023-5992?
CVE-2023-5992 affects Red Hat Enterprise Linux versions 7.0 to 9.4 across various architectures.
What is the nature of the vulnerability in CVE-2023-5992?
CVE-2023-5992 is a vulnerability in OpenSC related to insufficient side-channel resistance in PKCS#1 encryption padding removal.