Memory-cache side-channel attack in Libgcrypt - CVE-2018-0495
Published: June 16, 2018 / Updated: April 7, 2020
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to a leakage of information through memory caches when the affected library uses a private key to create Elliptic Curve Digital Signature Algorithm (ECDSA) signatures. A local attacker can conduct a memory-cache side-channel attack on ECDSA signatures and recover sensitive information, such as ECDSA private keys, which could be used to conduct further attacks.
Note: The vulnerability is known as the "Return Of the Hidden Number Problem" or ROHNP.
Affected software
Arch Linux
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
libgcrypt (Alpine package)
libressl (Alpine package)
nss-softokn (Red Hat package)
nss (Ubuntu package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openssl
libgcrypt
botan2
Data Computing Appliance (DCA)
EMC Cloud Tiering Appliance
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2018-0495
libgcrypt (Alpine package) - update to 1.7.10-r0
libressl (Alpine package) - update to 2.6.5-r0
nss-softokn (Red Hat package) - addressed in versions 3.28.3-9.el7_4, 3.36.0-6.el7_5, 3.36.0-6.el7_6
openssl - update to 1.1.1a-1.fc29
libgcrypt - addressed in versions 1.8.3-1.fc27, 1.8.3-1.fc28
botan2 - addressed in versions 2.7.0-1.fc27, 2.7.0-1.fc28
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
EMC Cloud Tiering Appliance - update to 12.1.0.65
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Arch Linux update for libgcrypt
- Slackware Linux update for libgcrypt
- Debian update for libgcrypt20
- OpenSUSE Linux update for libgcrypt
- OpenSUSE Linux update for libgcrypt
- OpenSUSE Linux update for libgcrypt
- Amazon Linux AMI update for openssl
- OpenSUSE Linux update for mozilla-nspr and mozilla-nss
- Ubuntu update for NSS
- Red Hat update for openssl
- Red Hat update for NSS
- Amazon Linux AMI update for nss, nss-softokn, nss-util, nspr
- Red Hat Enterprise Linux 7 update for nss-softokn
- Red Hat Enterprise Linux 7 update for nss-softokn
- Red Hat Enterprise Linux 7 update for nss-softokn
- Memory-cache side-channel attack in libgcrypt (Alpine package)
- Memory-cache side-channel attack in libressl (Alpine package)
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Fedora 28 update for libgcrypt
- Fedora 27 update for libgcrypt
- Fedora 27 update for botan2
- Fedora 28 update for botan2
- Fedora 29 update for openssl