Covert Timing Channel in OpenSSL - CVE-2024-13176
Published: February 4, 2025 / Updated: May 21, 2025
Vulnerability details
The vulnerability allows a remote attacker to recover a private key.
The vulnerability exists due to a timing side-channel in ECDSA signature computations. A remote attacker can recover the private key and decrypt data.
Successful exploitation of the vulnerability requires that the attacker's process must either be located in the same physical computer or must have a very fast network connection with low latency.
Affected software
PowerStore 9000T
PowerStore 5200T
PowerStore 5000T
PowerStore 7000T
PowerStore 3200T
PowerStore 9200T
PowerStore 3200Q
PowerStore 3000T
PowerStore 1200T
PowerStore 1000T
PowerStore 500T
LANTIME Operating System Firmware (LTOS)
PowerStoreT OS
PowerScale OneFS
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Slackware Linux
Basesystem Module
Legacy Module
Development Tools Module
Web and Scripting Module
Certifications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Oracle Solaris
JD Edwards World Security
IBM Concert Software
Sensor Proxy
Tenable Identity Exposure (formerly Tenable.ad)
IBM Spectrum Symphony
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
Session Smart Router
PowerProtect Data Manager
Traffix SDC
Nessus Network Monitor
MySQL Enterprise Backup
IBM DataPower Gateway
SecurityCenter
MySQL Server
Oracle Essbase
Oracle Database Server
MySQL Workbench
IBM CICS TX Advanced
RSA Authentication Manager
SmartFabric Manager
MySQL Connectors
Splunk Universal Forwarder
Orion Platform
PowerVM Hypervisor
mysql-selinux (Red Hat package)
openssl-1_1-debugsource
libopenssl-1_1-devel
libopenssl1_1-hmac
openssl-1_1
libopenssl1_1
libopenssl1_1-debuginfo
openssl-1_1-debuginfo
libopenssl1_1-debuginfo-32bit
libopenssl1_1-32bit
libopenssl-1_1-devel-32bit
libopenssl1_1-hmac-32bit
libopenssl1_1-32bit-debuginfo
openssl-1_1-doc
libopenssl1_1-hmac-64bit
libopenssl1_1-64bit
libopenssl-1_1-devel-64bit
libopenssl1_1-64bit-debuginfo
compat-openssl11-libs
compat-openssl11
compat-openssl11-debuginfo
compat-openssl11-debugsource
compat-openssl11-devel
openssl (Ubuntu package)
libssl1.1 (Ubuntu package)
openssl
openssl-solibs
libssl3 (Ubuntu package)
libopenssl3-64bit-debuginfo
libopenssl-3-devel-64bit
libopenssl3-64bit
openssl-3-doc
libopenssl3-32bit
libopenssl-3-devel-32bit
libopenssl3-32bit-debuginfo
libopenssl3-debuginfo
openssl-3-debugsource
openssl-3-debuginfo
openssl-3
libopenssl3
libopenssl-3-devel
openssl-doc
openssl-perl
openssl-libs
openssl-devel
libssl3t64 (Ubuntu package)
libopenssl-3-fips-provider-32bit
libopenssl-3-fips-provider-debuginfo
libopenssl-3-fips-provider
libopenssl-3-fips-provider-32bit-debuginfo
libopenssl-3-fips-provider-64bit-debuginfo
libopenssl-3-fips-provider-64bit
libopenssl-fips-provider
libopenssl-devel
mysql8.4 (Red Hat package)
nodejs24
nodejs24-docs
nodejs24-devel
nodejs24-debuginfo
npm24
nodejs24-debugsource
edk2 (Ubuntu package)
edk2-ovmf
edk2-help
edk2-aarch64
edk2-devel
python3-edk2-devel
edk2-debugsource
edk2-debuginfo
edk2
APEX Cloud Platform for Microsoft Azure
Storage Resource Manager
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
Cloud Pak for Data System - Cyclops
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2024-13176
IBM Concert Software - update to 2.0.0
Sensor Proxy - update to 1.0.12
Tenable Identity Exposure (formerly Tenable.ad) - update to 3.77.11
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.021
IBM Spectrum Symphony - update to 7.3.2 FP3
MySQL Server - addressed in versions 8.0.42, 8.4.5, 9.3.0
MySQL Workbench - update to 8.0.42
RSA Authentication Manager - update to 8.7 SP2 Patch 6
Splunk Universal Forwarder - addressed in versions 9.1.10, 9.2.7, 9.3.5, 9.4.3
IBM DataPower Gateway - addressed in versions 10.5.0.17, 10.6.0.5, 10.6.4.0
Oracle Database Server - update to 23.8
Orion Platform - update to 2025.2.1
PowerVM Hypervisor - addressed in versions FW950.D1, FW950.E0, FW1050.31, FW1050.40, FW1060.31, FW1060.40
mysql-selinux (Red Hat package) - update to 1.0.14-1.el10_0
openssl-1_1-debugsource - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl-1_1-devel - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-hmac - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1
openssl-1_1 - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1 - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-debuginfo - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
openssl-1_1-debuginfo - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.116.1
libopenssl1_1-32bit - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl-1_1-devel-32bit - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-hmac-32bit - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-hmac-64bit - update to 1.1.1l-150500.17.40.1
libopenssl1_1-64bit - addressed in versions 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl-1_1-devel-64bit - addressed in versions 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-64bit-debuginfo - addressed in versions 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
compat-openssl11-libs - update to 1.1.1m-13
compat-openssl11 - update to 1.1.1m-13
compat-openssl11-debuginfo - update to 1.1.1m-13
compat-openssl11-debugsource - update to 1.1.1m-13
compat-openssl11-devel - update to 1.1.1m-13
openssl (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.24, 3.0.2-0ubuntu1.19, 3.0.13-0ubuntu3.5, 3.3.1-2ubuntu2.1
libssl1.1 (Ubuntu package) - update to 1.1.1f-1ubuntu2.24
openssl - update to 1.1.1zb_p2
openssl-solibs - update to 1.1.1zb_p2
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.19
libopenssl3-64bit-debuginfo - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
libopenssl-3-devel-64bit - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
libopenssl3-64bit - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
openssl-3 - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl3 - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
openssl - update to 3.0.12-15
openssl-doc - update to 3.0.12-15
openssl-perl - update to 3.0.12-15
openssl-libs - update to 3.0.12-15
openssl-devel - update to 3.0.12-15
libssl3t64 (Ubuntu package) - addressed in versions 3.0.13-0ubuntu3.5, 3.3.1-2ubuntu2.1
libopenssl-3-fips-provider-32bit - addressed in versions 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-debuginfo - addressed in versions 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-fips-provider - addressed in versions 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit-debuginfo - addressed in versions 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-64bit-debuginfo - update to 3.1.4-150600.5.24.1
libopenssl-3-fips-provider-64bit - update to 3.1.4-150600.5.24.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
libopenssl-fips-provider - update to 3.5.0-150700.3.4.1
libopenssl-devel - update to 3.5.0-150700.3.4.1
openssl - update to 3.5.0-150700.3.4.1
PowerStoreT OS - update to 4.0.1.3-2494147
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell Secure Connect Gateway - update to 5.28.00.14
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect Client - update to 8.2.1
mysql8.4 (Red Hat package) - update to 8.4.6-2.el10_0
PowerScale OneFS - addressed in versions 9.10.1.3, 9.11.0.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
PowerProtect Data Manager - update to 19.19.0-15
nodejs24 - update to 24.18.1-150700.15.18.1
nodejs24-docs - update to 24.18.1-150700.15.18.1
nodejs24-devel - update to 24.18.1-150700.15.18.1
nodejs24-debuginfo - update to 24.18.1-150700.15.18.1
npm24 - update to 24.18.1-150700.15.18.1
nodejs24-debugsource - update to 24.18.1-150700.15.18.1
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2-ovmf - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-help - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-aarch64 - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-devel - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
python3-edk2-devel - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-debugsource - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-debuginfo - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2 - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
External References
- http://www.openwall.com/lists/oss-security/2025/01/20/2
- https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844
- https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467
- https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902
- https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65
- https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f
- https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded
- https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86
- https://openssl-library.org/news/secadv/20250120.txt
- https://security.netapp.com/advisory/ntap-20250124-0005/
Related Security Bulletins
- Timing side-channel during ECDSA signature computations in OpenSSL
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- Slackware Linux update for openssl
- SUSE update for openssl-3
- SUSE update for openssl-3
- SUSE update for openssl-1_1
- SUSE update for openssl-3
- Ubuntu update for openssl
- Ubuntu update for openssl
- SUSE update for openssl-1_1
- openEuler 22.03 LTS SP3 update for edk2
- openEuler 20.03 LTS SP4 update for edk2
- openEuler 24.03 LTS SP1 update for edk2
- openEuler 24.03 LTS update for edk2
- openEuler 22.03 LTS SP4 update for edk2
- openEuler 24.03 LTS SP1 update for compat-openssl11
- openEuler 24.03 LTS update for compat-openssl11
- Oracle Solaris update for third-party components
- Covert Timing Channel in Oracle Essbase
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in MySQL Server
- Covert Timing Channel in MySQL Enterprise Backup
- Multiple vulnerabilities in MySQL Connectors
- Multiple vulnerabilities in MySQL Workbench
- Tenable Security Center update for third-party components
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in IBM CICS TX Advanced
- Tenable Identity Exposure update for third-party components
- Tenable Sensor Proxy update for third-party components
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- SUSE update for openssl-1_1
- RSA Authentication Manager update for third-party components
- SUSE update for openssl-1_1
- Meinberg LANTIME firmware update for third-party components (March 2025)
- IBM PowerVM Hypervisor update for OpenSSL
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Timing attack in F5 Traffix SDC OpenSSL component
- Multiple vulnerabilities in Tenable Network Monitor
- Multiple vulnerabilities in Dell PowerStoreT OS
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Dell SmartFabric Manager update for third-party components
- IBM DataPower Gateway update for OpenSSL
- SUSE update for openssl-3
- Splunk Universal Forwarder update for third-party components
- Covert Timing Channel in JD Edwards World Security
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in SolarWinds Platform
- Dell PowerScale OneFS update for third-party components
- Multiple vulnerabilities in IBM Concert Software
- Red Hat Enterprise Linux 9 update for the mysql:8.4 module
- Anolis OS update for openssl
- Red Hat Enterprise Linux 10 update for multiple packages
- Ubuntu update for edk2
- Ubuntu update for edk2
- Juniper Session Smart Router update for third-party components
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management
- IBM Spectrum Symphony update for OpenSSL
- Multiple vulnerabilities in IBM Cloud Pak for Data System - Cyclops
- SUSE update for openssl, openssl-3