Covert Timing Channel in OpenSSL - CVE-2024-13176

 

Covert Timing Channel in OpenSSL - CVE-2024-13176

Published: February 4, 2025 / Updated: May 21, 2025


Vulnerability identifier: #VU103600
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-13176
CWE-ID: CWE-385
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to recover a private key.

The vulnerability exists due to a timing side-channel in ECDSA signature computations. A remote attacker can recover the private key and decrypt data.

Successful exploitation of the vulnerability requires that the attacker's process must either be located in the same physical computer or must have a very fast network connection with low latency.


Affected software

OpenSSL
PowerStore 9000T
PowerStore 5200T
PowerStore 5000T
PowerStore 7000T
PowerStore 3200T
PowerStore 9200T
PowerStore 3200Q
PowerStore 3000T
PowerStore 1200T
PowerStore 1000T
PowerStore 500T
LANTIME Operating System Firmware (LTOS)
PowerStoreT OS
PowerScale OneFS
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Slackware Linux
Basesystem Module
Legacy Module
Development Tools Module
Web and Scripting Module
Certifications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Oracle Solaris
JD Edwards World Security
IBM Concert Software
Sensor Proxy
Tenable Identity Exposure (formerly Tenable.ad)
IBM Spectrum Symphony
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
Session Smart Router
PowerProtect Data Manager
Traffix SDC
Nessus Network Monitor
MySQL Enterprise Backup
IBM DataPower Gateway
SecurityCenter
MySQL Server
Oracle Essbase
Oracle Database Server
MySQL Workbench
IBM CICS TX Advanced
RSA Authentication Manager
SmartFabric Manager
MySQL Connectors
Splunk Universal Forwarder
Orion Platform
PowerVM Hypervisor
mysql-selinux (Red Hat package)
openssl-1_1-debugsource
libopenssl-1_1-devel
libopenssl1_1-hmac
openssl-1_1
libopenssl1_1
libopenssl1_1-debuginfo
openssl-1_1-debuginfo
libopenssl1_1-debuginfo-32bit
libopenssl1_1-32bit
libopenssl-1_1-devel-32bit
libopenssl1_1-hmac-32bit
libopenssl1_1-32bit-debuginfo
openssl-1_1-doc
libopenssl1_1-hmac-64bit
libopenssl1_1-64bit
libopenssl-1_1-devel-64bit
libopenssl1_1-64bit-debuginfo
compat-openssl11-libs
compat-openssl11
compat-openssl11-debuginfo
compat-openssl11-debugsource
compat-openssl11-devel
openssl (Ubuntu package)
libssl1.1 (Ubuntu package)
openssl
openssl-solibs
libssl3 (Ubuntu package)
libopenssl3-64bit-debuginfo
libopenssl-3-devel-64bit
libopenssl3-64bit
openssl-3-doc
libopenssl3-32bit
libopenssl-3-devel-32bit
libopenssl3-32bit-debuginfo
libopenssl3-debuginfo
openssl-3-debugsource
openssl-3-debuginfo
openssl-3
libopenssl3
libopenssl-3-devel
openssl-doc
openssl-perl
openssl-libs
openssl-devel
libssl3t64 (Ubuntu package)
libopenssl-3-fips-provider-32bit
libopenssl-3-fips-provider-debuginfo
libopenssl-3-fips-provider
libopenssl-3-fips-provider-32bit-debuginfo
libopenssl-3-fips-provider-64bit-debuginfo
libopenssl-3-fips-provider-64bit
libopenssl-fips-provider
libopenssl-devel
mysql8.4 (Red Hat package)
nodejs24
nodejs24-docs
nodejs24-devel
nodejs24-debuginfo
npm24
nodejs24-debugsource
edk2 (Ubuntu package)
edk2-ovmf
edk2-help
edk2-aarch64
edk2-devel
python3-edk2-devel
edk2-debugsource
edk2-debuginfo
edk2
APEX Cloud Platform for Microsoft Azure
Storage Resource Manager
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
Cloud Pak for Data System - Cyclops
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2024-13176

Install update from vendor's website.

OpenSSL - addressed in versions 1.0.2zl, 1.1.1zb, 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.1
IBM Concert Software - update to 2.0.0
Sensor Proxy - update to 1.0.12
Tenable Identity Exposure (formerly Tenable.ad) - update to 3.77.11
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.021
IBM Spectrum Symphony - update to 7.3.2 FP3
MySQL Server - addressed in versions 8.0.42, 8.4.5, 9.3.0
MySQL Workbench - update to 8.0.42
RSA Authentication Manager - update to 8.7 SP2 Patch 6
Splunk Universal Forwarder - addressed in versions 9.1.10, 9.2.7, 9.3.5, 9.4.3
IBM DataPower Gateway - addressed in versions 10.5.0.17, 10.6.0.5, 10.6.4.0
Oracle Database Server - update to 23.8
Orion Platform - update to 2025.2.1
PowerVM Hypervisor - addressed in versions FW950.D1, FW950.E0, FW1050.31, FW1050.40, FW1060.31, FW1060.40
mysql-selinux (Red Hat package) - update to 1.0.14-1.el10_0
openssl-1_1-debugsource - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl-1_1-devel - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-hmac - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1
openssl-1_1 - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1 - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-debuginfo - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
openssl-1_1-debuginfo - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.116.1
libopenssl1_1-32bit - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl-1_1-devel-32bit - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-hmac-32bit - addressed in versions 1.1.1d-2.116.1, 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.100.1, 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-hmac-64bit - update to 1.1.1l-150500.17.40.1
libopenssl1_1-64bit - addressed in versions 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl-1_1-devel-64bit - addressed in versions 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
libopenssl1_1-64bit-debuginfo - addressed in versions 1.1.1l-150500.17.40.1, 1.1.1w-150600.5.12.2
compat-openssl11-libs - update to 1.1.1m-13
compat-openssl11 - update to 1.1.1m-13
compat-openssl11-debuginfo - update to 1.1.1m-13
compat-openssl11-debugsource - update to 1.1.1m-13
compat-openssl11-devel - update to 1.1.1m-13
openssl (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.24, 3.0.2-0ubuntu1.19, 3.0.13-0ubuntu3.5, 3.3.1-2ubuntu2.1
libssl1.1 (Ubuntu package) - update to 1.1.1f-1ubuntu2.24
openssl - update to 1.1.1zb_p2
openssl-solibs - update to 1.1.1zb_p2
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.19
libopenssl3-64bit-debuginfo - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
libopenssl-3-devel-64bit - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
libopenssl3-64bit - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
openssl-3 - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl3 - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.72.1, 3.0.8-150500.5.51.1, 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
openssl - update to 3.0.12-15
openssl-doc - update to 3.0.12-15
openssl-perl - update to 3.0.12-15
openssl-libs - update to 3.0.12-15
openssl-devel - update to 3.0.12-15
libssl3t64 (Ubuntu package) - addressed in versions 3.0.13-0ubuntu3.5, 3.3.1-2ubuntu2.1
libopenssl-3-fips-provider-32bit - addressed in versions 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-debuginfo - addressed in versions 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-fips-provider - addressed in versions 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit-debuginfo - addressed in versions 3.1.4-150600.5.24.1, 3.2.3-150700.5.5.1, 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-64bit-debuginfo - update to 3.1.4-150600.5.24.1
libopenssl-3-fips-provider-64bit - update to 3.1.4-150600.5.24.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
libopenssl-fips-provider - update to 3.5.0-150700.3.4.1
libopenssl-devel - update to 3.5.0-150700.3.4.1
openssl - update to 3.5.0-150700.3.4.1
PowerStoreT OS - update to 4.0.1.3-2494147
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell Secure Connect Gateway - update to 5.28.00.14
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect Client - update to 8.2.1
mysql8.4 (Red Hat package) - update to 8.4.6-2.el10_0
PowerScale OneFS - addressed in versions 9.10.1.3, 9.11.0.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
PowerProtect Data Manager - update to 19.19.0-15
nodejs24 - update to 24.18.1-150700.15.18.1
nodejs24-docs - update to 24.18.1-150700.15.18.1
nodejs24-devel - update to 24.18.1-150700.15.18.1
nodejs24-debuginfo - update to 24.18.1-150700.15.18.1
npm24 - update to 24.18.1-150700.15.18.1
nodejs24-debugsource - update to 24.18.1-150700.15.18.1
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2-ovmf - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-help - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-aarch64 - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-devel - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
python3-edk2-devel - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-debugsource - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-debuginfo - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2 - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18

External References

Related Security Bulletins