CVE-2023-6240
published 2024-02-04CVE-2023-6240: A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt…
PriorityP338medium6.5CVSS 3.1
AVNACHPRNUINSUCHILAN
EPSS
0.97%
58.3th percentile
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
vendor_paloalto·2025-05-14·CVSS 5.9
CVE-2024-29995 [MEDIUM] CWE-1240 PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the applicability of CVEs related to the Marvin attack on PAN-OS. While we did not determine that any of these CVEs have significant impact on our PAN-OS software, some were fixed anyway out of an abundance of caution. You can also review more details about the Marvin attack if helpful. CVE Summary CVE-2024-29995 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable opensc library. CVE-2024-26306 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable iperf3 component. CVE-2024-23170 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable Mbed TLS component. CVE-2024-21484 This CVE does not aff
Red Hat
kernel: Marvin vulnerability side-channel leakage in the RSA decryption operation
vendor_redhat·2023-09-25·CVSS 6.5
CVE-2023-6240 [MEDIUM] CWE-203 kernel: Marvin vulnerability side-channel leakage in the RSA decryption operation
kernel: Marvin vulnerability side-channel leakage in the RSA decryption operation
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red H
Debian
CVE-2023-6240: linux - A Marvin vulnerability side-channel leakage was found in the RSA decryption oper...
vendor_debian·2023·CVSS 6.5
CVE-2023-6240 [MEDIUM] CVE-2023-6240: linux - A Marvin vulnerability side-channel leakage was found in the RSA decryption oper...
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
CVE-2023-6240: A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel
osv·2024-02-04·CVSS 6.5
CVE-2023-6240 [MEDIUM] CVE-2023-6240: A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
GHSA
GHSA-5gvr-285q-pwc3: A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel
ghsa_unreviewed·2024-02-04
CVE-2023-6240 [MEDIUM] CWE-203 GHSA-5gvr-285q-pwc3: A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:1881https://access.redhat.com/errata/RHSA-2024:1882https://access.redhat.com/errata/RHSA-2024:2758https://access.redhat.com/errata/RHSA-2024:3414https://access.redhat.com/errata/RHSA-2024:3421https://access.redhat.com/errata/RHSA-2024:3618https://access.redhat.com/errata/RHSA-2024:3627https://access.redhat.com/security/cve/CVE-2023-6240https://bugzilla.redhat.com/show_bug.cgi?id=2250843https://people.redhat.com/~hkario/marvin/https://securitypitfalls.wordpress.com/2023/10/16/experiment-with-side-channel-attacks-yourself/https://access.redhat.com/errata/RHSA-2024:1881https://access.redhat.com/errata/RHSA-2024:1882https://access.redhat.com/errata/RHSA-2024:2758https://access.redhat.com/errata/RHSA-2024:3414https://access.redhat.com/errata/RHSA-2024:3421https://access.redhat.com/errata/RHSA-2024:3618https://access.redhat.com/errata/RHSA-2024:3627https://access.redhat.com/security/cve/CVE-2023-6240https://bugzilla.redhat.com/show_bug.cgi?id=2250843https://people.redhat.com/~hkario/marvin/https://security.netapp.com/advisory/ntap-20240628-0002/https://securitypitfalls.wordpress.com/2023/10/16/experiment-with-side-channel-attacks-yourself/
2024-02-04
Published