CVE-2021-33560
published 2021-06-08CVE-2021-33560: Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.34%
81.7th percentile
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libgcrypt20 | < libgcrypt20 1.9.4-2 (bookworm) | libgcrypt20 1.9.4-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnupg | libgcrypt | < 1.8.8 | 1.8.8 |
| gnupg | libgcrypt | >= 1.9.0 < 1.9.3 | 1.9.3 |
| msrc | cm1_libgcrypt_1.8.7-2_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_service_communication_proxy | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (libgcrypt) — CVE-2021-33560
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-33560 [HIGH] Oracle Oracle Communications Risk Matrix: Configuration (libgcrypt) — CVE-2021-33560
Oracle Oracle Communications Risk Matrix: Configuration (libgcrypt) vulnerability
CVE: CVE-2021-33560
CVSS: 7.5
Protocol: TCP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Measurements (libgcrypt) — CVE-2021-33560
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2021-33560 [HIGH] Oracle Oracle Communications Risk Matrix: Measurements (libgcrypt) — CVE-2021-33560
Oracle Oracle Communications Risk Matrix: Measurements (libgcrypt) vulnerability
CVE: CVE-2021-33560
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2021-09-16
CVE-2021-33560 Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Libgcrypt could be made to expose sensitive information.
USN-5080-1 fixed several vulnerabilities in Libgcrypt. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Libgcrypt incorrectly handled ElGamal encryption. An
attacker could possibly use this issue to recover sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2021-09-16
CVE-2021-33560 Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Libgcrypt could be made to expose sensitive information.
It was discovered that Libgcrypt incorrectly handled ElGamal encryption. An
attacker could possibly use this issue to recover sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libgcrypt: ElGamal implementation allows plaintext recovery
vendor_redhat·2021-07-20·CVSS 7.5
CVE-2021-40528 [HIGH] libgcrypt: ElGamal implementation allows plaintext recovery
libgcrypt: ElGamal implementation allows plaintext recovery
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
A flaw was found in libgcrypt's ElGamal implementation, where it allows plain text recovery. During the interaction between two cryptographic libraries, a certain combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against
Microsoft
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm and the window size is not chosen appro
vendor_msrc·2021-06-08·CVSS 7.5
CVE-2021-33560 [HIGH] CWE-203 Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm and the window size is not chosen appro
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm and the window size is not chosen appropriately. This for example affects use of ElGamal in OpenPGP.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If im
Red Hat
libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm
vendor_redhat·2021-06-02·CVSS 7.5
CVE-2021-33560 [HIGH] CWE-327 libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm
libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
A side-channel attack flaw was found in the way libgcrypt implemented Elgamal encryption. This flaw allows an attacker to decrypt parts of ciphertext encrypted using Elgamal, for example, when using OpenPGP. The highest threat from this vulnerability is to confidentiality.
Package: libgcrypt (Red Hat Enterprise Linux 6) - Out of support scope
Package: libgcrypt (Red Hat Enterprise Linux 7) - Out of sup
Debian
CVE-2021-33560: libgcrypt20 - Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption beca...
vendor_debian·2021·CVSS 7.5
CVE-2021-33560 [HIGH] CVE-2021-33560: libgcrypt20 - Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption beca...
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
Scope: local
bookworm: resolved (fixed in 1.9.4-2)
bullseye: open
forky: resolved (fixed in 1.9.4-2)
sid: resolved (fixed in 1.9.4-2)
trixie: resolved (fixed in 1.9.4-2)
GHSA
GHSA-g9p5-p7h5-p2wg: Libgcrypt before 1
ghsa_unreviewed·2022-05-24
CVE-2021-33560 [HIGH] CWE-203 GHSA-g9p5-p7h5-p2wg: Libgcrypt before 1
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. (There is also an interoperability problem because the selection of the k integer value does not properly consider the differences between basic ElGamal encryption and generalized ElGamal encryption.) This, for example, affects use of ElGamal in OpenPGP.
OSV
CVE-2021-33560: Libgcrypt before 1
osv·2021-06-08·CVSS 7.5
CVE-2021-33560 [HIGH] CVE-2021-33560: Libgcrypt before 1
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://dev.gnupg.org/T5305https://dev.gnupg.org/T5328https://dev.gnupg.org/T5466https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61https://lists.debian.org/debian-lts-announce/2021/06/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/https://security.gentoo.org/glsa/202210-13https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://dev.gnupg.org/T5305https://dev.gnupg.org/T5328https://dev.gnupg.org/T5466https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61https://lists.debian.org/debian-lts-announce/2021/06/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/https://security.gentoo.org/glsa/202210-13https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-08
Published