Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676.
References
| Link | Resource |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/257676 | Third Party Advisory |
| https://www.ibm.com/support/pages/node/7145168 | Vendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/257676 | Third Party Advisory |
| https://www.ibm.com/support/pages/node/7145168 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2024-03-26 14:15
Updated : 2025-07-25 21:09
NVD link : CVE-2023-33855
Mitre link : CVE-2023-33855
CVE.ORG link : CVE-2023-33855
JSON object : View
Products Affected
linux
- linux_kernel
ibm
- aix
- i
- common_cryptographic_architecture
CWE
CWE-385
Covert Timing Channel
