CVE-2024-45191: Medium severity matrix olm vulnerability
An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45191?
CVE-2024-45191 has a high severity due to its vulnerability to cache-timing attacks in the AES implementation.
How do I fix CVE-2024-45191?
To fix CVE-2024-45191, update Matrix libolm to version 3.2.17 or later.
What impact does CVE-2024-45191 have on data security?
CVE-2024-45191 can allow attackers to exploit timing discrepancies to gain sensitive information from the AES implementation.
Which versions of Matrix libolm are affected by CVE-2024-45191?
CVE-2024-45191 affects Matrix libolm versions up to and including 3.2.16.
Who is impacted by CVE-2024-45191?
Users of Matrix libolm versions 3.2.16 and earlier are impacted by CVE-2024-45191.