rpm package
almalinux/libgcrypt-devel
pkg:rpm/almalinux/libgcrypt-devel
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-41989 | Med | 6.7 | < 1.8.5-8.el8_10 | 1.8.5-8.el8_10 | Apr 23, 2026 | Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt. | |
| CVE-2024-2236 | Med | 5.9 | < 1.10.0-11.el9 | 1.10.0-11.el9 | Mar 6, 2024 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts. | |
| CVE-2021-40528 | Med | 5.9 | < 1.8.5-7.el8_6 | 1.8.5-7.el8_6 | Sep 6, 2021 | The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, a | |
| CVE-2021-33560 | Hig | 7.5 | < 1.8.5-6.el8 | 1.8.5-6.el8 | Jun 8, 2021 | Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP. |
- affected < 1.8.5-8.el8_10fixed 1.8.5-8.el8_10
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
- affected < 1.10.0-11.el9fixed 1.10.0-11.el9
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.
- affected < 1.8.5-7.el8_6fixed 1.8.5-7.el8_6
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, a
- affected < 1.8.5-6.el8fixed 1.8.5-6.el8
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.