CVE-2019-12904
published 2019-06-20CVE-2019-12904: In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
2.06%
79.2th percentile
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r2 | 1.8.4-r2 |
| gnupg | libgcrypt | >= 0 < 1.8.3-r1 | 1.8.3-r1 |
| gnupg | libgcrypt | >= 0 < 1.8.3-r1 | 1.8.3-r1 |
| gnupg | libgcrypt | >= 0 < 1.8.4-r1 | 1.8.4-r1 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w862-39x5-q88x: In Libgcrypt 1
ghsa_unreviewed·2022-05-24
CVE-2019-12904 [MEDIUM] CWE-668 GHSA-w862-39x5-q88x: In Libgcrypt 1
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.)
OSV
CVE-2019-12904: In Libgcrypt 1
osv·2019-06-20·CVSS 5.9
CVE-2019-12904 [MEDIUM] CVE-2019-12904: In Libgcrypt 1
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack
Red Hat
Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack
vendor_redhat·2019-07-16·CVSS 5.9
CVE-2019-12904 [MEDIUM] CWE-385 Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack
Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack
[Disputed] A vulnerability has been identified in Libgcrypt due to a flaw in its C implementation of AES. This vulnerability enables a remote attacker to perform a flush-and-reload side-channel attack, potentially accessing sensitive information. The vulnerability arises from the availability of phy
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12904 mingw-libgcrypt: Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack [epel-7]
bugzilla·2019-09-17·CVSS 5.9
CVE-2019-12904 [MEDIUM] CVE-2019-12904 mingw-libgcrypt: Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack [epel-7]
CVE-2019-12904 mingw-libgcrypt: Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedp
Bugzilla
CVE-2019-12904 libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack [fedora-all]
bugzilla·2019-07-16·CVSS 5.9
CVE-2019-12904 [MEDIUM] CVE-2019-12904 libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack [fedora-all]
CVE-2019-12904 libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2019-12904 Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack
bugzilla·2019-07-16·CVSS 5.9
CVE-2019-12904 [MEDIUM] CVE-2019-12904 Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack
CVE-2019-12904 Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.)
External Reference:
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12904.html
Discussion:
Created libgcrypt tracking bugs for this issue:
Affects: fedora-all [bug 1730321]
---
This seems more a theoretical attack possibility than and practical one. This seems to be the same opinion from upstream maintainers at https://dev.gnupg.org/T4541.
Given that, the patches looks like much
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.htmlhttps://dev.gnupg.org/T4541https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.htmlhttps://dev.gnupg.org/T4541https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
2019-06-20
Published