Medium severity5.9OSV Advisory· Published Jan 31, 2024· Updated Jun 17, 2026
CVE-2024-0914
CVE-2024-0914
Description
A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21v2.3.2, v2.3.3, v2.4.3, …+ 1 more
- (no CPE)range: v2.3.2, v2.3.3, v2.4.3, …
- cpe:2.3:a:opencryptoki_project:opencryptoki:*:*:*:*:*:*:*:*range: <3.23.0
- osv-coords16 versionspkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5pkg:rpm/opensuse/openCryptoki&distro=openSUSE%20Leap%2015.5pkg:rpm/almalinux/opencryptoki-develpkg:rpm/almalinux/opencryptoki-ep11tokpkg:rpm/almalinux/opencryptokipkg:rpm/almalinux/opencryptoki-ccatokpkg:rpm/almalinux/opencryptoki-icatokpkg:rpm/almalinux/opencryptoki-icsftokpkg:rpm/almalinux/opencryptoki-libspkg:rpm/almalinux/opencryptoki-tpmtokpkg:rpm/almalinux/opencryptoki-swtokpkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/opensuse/openCryptoki&distro=openSUSE%20Tumbleweedpkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
< 3.23.0-150500.3.3.13+ 15 more
- (no CPE)range: < 3.23.0-150500.3.3.13
- (no CPE)range: < 3.23.0-150500.3.3.13
- (no CPE)range: < 3.21.0-9.el9_3.alma.1
- (no CPE)range: < 3.21.0-9.el9_3.alma.1
- (no CPE)range: < 3.21.0-9.el9_3.alma.1
- (no CPE)range: < 3.21.0-9.el9_3.alma.1
- (no CPE)range: < 3.21.0-9.el9_3.alma.1
- (no CPE)range: < 3.21.0-9.el9_3.alma.1
- (no CPE)range: < 3.21.0-9.el9_3.alma.1
- (no CPE)range: < 3.21.0-10.el8_9.alma.1
- (no CPE)range: < 3.21.0-9.el9_3.alma.1
- (no CPE)range: < 3.17.0-5.9.2
- (no CPE)range: < 3.23.0-4.1
- (no CPE)range: < 3.23.0-150500.3.3.13
- (no CPE)range: < 3.17.0-5.9.2
- (no CPE)range: < 3.17.0-5.9.2
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatch
- access.redhat.com/security/cve/CVE-2024-0914nvdThird Party Advisory
- people.redhat.com/~hkario/marvin/nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2024:1239nvd
- access.redhat.com/errata/RHSA-2024:1411nvd
- access.redhat.com/errata/RHSA-2024:1608nvd
- access.redhat.com/errata/RHSA-2024:1856nvd
- access.redhat.com/errata/RHSA-2024:1992nvd
News mentions
0No linked articles in our index yet.