Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2024-2236
Libgcrypt vulnerability analysis and mitigation

Overview

A timing-based side-channel vulnerability (CVE-2024-2236) was discovered in libgcrypt's RSA implementation. The vulnerability was disclosed on March 6, 2024, affecting the libgcrypt cryptographic library. This flaw could potentially allow remote attackers to perform Bleichenbacher-style attacks, leading to the decryption of RSA ciphertexts (NVD, Red Hat).

Technical details

The vulnerability is classified as a timing discrepancy issue (CWE-208) with a CVSS v3.1 base score of 5.9 (Medium). The attack vector is network-based (AV:N) with high attack complexity (AC:H), requiring no privileges (PR:N) or user interaction (UI:N). The scope is unchanged (S:U) with high confidentiality impact (C:H) but no impact on integrity (I:N) or availability (A:N) (NVD).

Impact

The vulnerability affects all RSA padding modes including PKCS#1 v1.5, RSA-OAEP, and RSASVE. If successfully exploited, an attacker could potentially decrypt RSA ciphertexts, compromising the confidentiality of encrypted communications (Red Hat Bugzilla).

Exploitability

To successfully exploit this vulnerability, an attacker would need to be able to send a large number of trial messages for decryption across a network. The attack follows a Bleichenbacher-style approach, utilizing timing differences in the RSA implementation (Red Hat Bugzilla).

Mitigation and workarounds

Red Hat has released security updates to address this vulnerability in Red Hat Enterprise Linux 9 through RHSA-2024:9404. The fixes are available in the Red Hat libgcrypt mirror repository (Red Hat Errata, Red Hat Bugzilla).

Community reactions

The libgcrypt developers have classified this as a low severity issue, as indicated in Ubuntu's security advisory. The vulnerability is being tracked upstream through the GnuPG development portal (Ubuntu).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

libgcrypt20

Affected

bullseye

libgcrypt20

Affected

sid

libgcrypt20

Affected

trixie

libgcrypt20

Affected

SourceThis report was generated using AI

Related Libgcrypt vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-33560HIGH7.5
  • NixOS logoNixOS
  • libgcrypt-devel-debuginfo
NoYesJun 08, 2021
CVE-2026-41989MEDIUM6.7
  • Libgcrypt logoLibgcrypt
  • thunderbird
NoYesApr 23, 2026
CVE-2024-2236MEDIUM5.9
  • Libgcrypt logoLibgcrypt
  • libgcrypt20-x86-64-v3
NoYesMar 06, 2024
CVE-2021-40528MEDIUM5.9
  • NixOS logoNixOS
  • kernel
NoYesSep 06, 2021
CVE-2026-41990MEDIUM4
  • Libgcrypt logoLibgcrypt
  • libgcrypt
NoYesApr 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management