CVE-2023-6258: Pkcs11-provider: side-channel proofing pkcs#1 1.5 paths
A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in a Bleichenbacher-like security flaw, potentially enabling a side-channel attack on PKCS#1 1.5 decryption.
Other sources
Side-channel proofing PKCS#1 1.5 paths (Marvin)
Ref: https://github.com/latchset/pkcs11-provider/pull/308
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6258?
CVE-2023-6258 has been classified as a moderate severity vulnerability due to potential security implications related to side-channel attacks.
How do I fix CVE-2023-6258?
To mitigate CVE-2023-6258, update the pkcs11-provider to version 0.2 or later, ensuring you are no longer using affected versions.
What software is affected by CVE-2023-6258?
CVE-2023-6258 affects pkcs11-provider versions up to, but not including, 0.2 from Red Hat and version 0.1 from Latchset.
What type of attack is associated with CVE-2023-6258?
CVE-2023-6258 is associated with a Bleichenbacher-like vulnerability that may allow for side-channel attacks.
What is pkcs11-provider in relation to CVE-2023-6258?
Pkcs11-provider is a software package involved in cryptographic operations that has been identified to have the vulnerability CVE-2023-6258.