/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-x42q-p28c-pg95

Published

Last updated

https://images.chainguard.dev/security/CGA-x42q-p28c-pg95
Package

opentofu-1.6

Repository

Chainguard

Latest Update
Fixed
Fixed Version

1.6.3-r1

Aliases
  • GHSA-9763-4f94-gfch

Severity

Unknown

Summary

CIRCL's Kyber: timing side-channel (kyberslash2)

Description

Impact

On some platforms, when an attacker can time decapsulation of Kyber on forged cipher texts, they could possibly learn (parts of) the secret key.

Does not apply to ephemeral usage, such as when used in the regular way in TLS.

Patches

Patched in 1.3.7.

References

  • kyberslash.cr.yp.to

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs