/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-c7p6-7wx6-prjq

Published

Last updated

https://images.chainguard.dev/security/CGA-c7p6-7wx6-prjq
Package

sccache

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • GHSA-4grx-2x9w-596c

Severity

Unknown

Summary

Marvin Attack: potential key recovery through timing sidechannels

Description

The Marvin Attack is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.

A recent survey of RSA implementations found that the Rust rsa crate is one of many implementations vulnerable to this attack.

No fixed version is available at this time.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs