Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-java |
|
| Vendors & Products |
Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-java |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected. | |
| Title | ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash) | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-08-09T20:56:37.119Z
Reserved: 2026-07-28T05:07:53.475Z
Link: CVE-2024-14041
Updated: 2026-07-28T12:55:00.550Z
Status : Undergoing Analysis
Published: 2026-07-28T08:17:12.367
Modified: 2026-07-30T16:27:52.133
Link: CVE-2024-14041
No data.
OpenCVE Enrichment
Updated: 2026-08-03T15:52:56Z