CVE-2023-5981: Gnutls: timing side-channel in the rsa-psk authentication
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
Other sources
GNU GnuTLS could allow a remote attacker to obtain sensitive information, caused by a timing sidechannel issue during RSA-PSK key exchange. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
— IBM
gnutls: timing side-channel in the RSA-PSK authentication https://gitlab.com/gnutls/gnutls/-/issues/1511
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-5981?
CVE-2023-5981 is a vulnerability found in the RSA-PSK key exchange in GnuTLS, where response times to malformed ciphertexts differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
What is the severity of CVE-2023-5981?
The severity of CVE-2023-5981 is high with a CVSS severity score of 7.4.
Which software versions are affected by CVE-2023-5981?
GnuTLS versions up to and excluding 3.8.2, Gnu Gnutls version 1.5.0, Redhat Linux versions 8.0 and 9.0, and Fedora versions 37 and 38 are affected by CVE-2023-5981.
How can I fix CVE-2023-5981?
To fix CVE-2023-5981, upgrade GnuTLS to version 3.8.3 or higher.
Where can I find more information about CVE-2023-5981?
More information about CVE-2023-5981 can be found on the Red Hat Security Advisory and Bugzilla pages, as well as the GnuTLS GitLab issue.