First published: Tue Nov 21 2023(Updated: )
A flaw found that is Marvin Attack vulnerability side-channel leakage in the RSA decryption operation. References: <a href="https://securitypitfalls.wordpress.com/2023/10/16/experiment-with-side-channel-attacks-yourself/">https://securitypitfalls.wordpress.com/2023/10/16/experiment-with-side-channel-attacks-yourself/</a> <a href="https://people.redhat.com/~hkario/marvin/">https://people.redhat.com/~hkario/marvin/</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | ||
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6240 has been classified with a medium severity level due to its potential to leak sensitive information through side-channel attacks.
To mitigate CVE-2023-6240, it is advised to apply the latest security updates for the Linux kernel or Red Hat Enterprise Linux as suggested in the security advisories.
CVE-2023-6240 affects multiple versions of the Linux kernel and Red Hat Enterprise Linux 7.0, 8.0, and 9.0.
CVE-2023-6240 is a side-channel leakage vulnerability associated with the RSA decryption operation.
While exploitation of CVE-2023-6240 may require local access, side-channel attacks could potentially lead to remote information leakage.