CVE-2024-0553
published 2024-01-16CVE-2024-0553: A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.61%
73.3th percentile
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.7.9-2+deb12u2 (bookworm) | gnutls28 3.7.9-2+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| gnu | gnutls | < 3.8.3 | 3.8.3 |
| msrc | azl3_gnutls_3.8.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_gnutls_3.8.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_gnutls_3.7.11-1_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| ubuntu | gnutls28 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 7.5
CVE-2026-33846 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker
could possibly use this issue to recover sensitive information. This
issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this
issue to cause GnuTLS to consume resources, leading to a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)
Luigino Camastra discovered that GnuTLS incorrectly handled certain
PKCS11 token labels. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a deni
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2024-01-22·CVSS 7.5
CVE-2024-0553 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker could
possibly use this issue to recover sensitive information. (CVE-2024-0553)
It was discovered that GnuTLS incorrectly handled certain certificate
chains with a cross-signing loop. A remote attacker could possibly use this
issue to cause GnuTLS to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10.
(CVE-2024-0567)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: incomplete fix for CVE-2023-5981
vendor_redhat·2024-01-16·CVSS 5.9
CVE-2024-0553 [MEDIUM] CWE-203 gnutls: incomplete fix for CVE-2023-5981
gnutls: incomplete fix for CVE-2023-5981
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leaka
Microsoft
Gnutls: incomplete fix for cve-2023-5981
vendor_msrc·2024-01-09·CVSS 7.5
CVE-2024-0553 [HIGH] CWE-203 Gnutls: incomplete fix for cve-2023-5981
Gnutls: incomplete fix for cve-2023-5981
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.co
Debian
CVE-2024-0553: gnutls28 - A vulnerability was found in GnuTLS. The response times to malformed ciphertexts...
vendor_debian·2024·CVSS 5.9
CVE-2024-0553 [MEDIUM] CVE-2024-0553: gnutls28 - A vulnerability was found in GnuTLS. The response times to malformed ciphertexts...
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
Scope: local
bookworm: resolved (fixed in 3.7.9-2+deb12u2)
bullseye: resolved (fixed in 3.7.1-5+deb11u5)
forky: resolved (fixed in 3.8.3-1)
sid: resolved (fixed in 3.8.3-1)
trixie: resolved (fixed in 3.8.3-1)
OSV
gnutls28 vulnerabilities
osv·2024-01-22·CVSS 7.5
CVE-2024-0553 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker could
possibly use this issue to recover sensitive information. (CVE-2024-0553)
It was discovered that GnuTLS incorrectly handled certain certificate
chains with a cross-signing loop. A remote attacker could possibly use this
issue to cause GnuTLS to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10.
(CVE-2024-0567)
OSV
CVE-2024-0553: A vulnerability was found in GnuTLS
osv·2024-01-16·CVSS 5.9
CVE-2024-0553 [MEDIUM] CVE-2024-0553: A vulnerability was found in GnuTLS
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
GHSA
GHSA-x697-v25m-6phv: A vulnerability was found in GnuTLS
ghsa_unreviewed·2024-01-16·CVSS 5.9
CVE-2024-0553 [MEDIUM] CWE-203 GHSA-x697-v25m-6phv: A vulnerability was found in GnuTLS
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:0533https://access.redhat.com/errata/RHSA-2024:0627https://access.redhat.com/errata/RHSA-2024:0796https://access.redhat.com/errata/RHSA-2024:1082https://access.redhat.com/errata/RHSA-2024:1108https://access.redhat.com/errata/RHSA-2024:1383https://access.redhat.com/errata/RHSA-2024:2094https://access.redhat.com/security/cve/CVE-2024-0553https://bugzilla.redhat.com/show_bug.cgi?id=2258412https://gitlab.com/gnutls/gnutls/-/issues/1522https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.htmlhttp://www.openwall.com/lists/oss-security/2024/01/19/3https://access.redhat.com/errata/RHSA-2024:0533https://access.redhat.com/errata/RHSA-2024:0627https://access.redhat.com/errata/RHSA-2024:0796https://access.redhat.com/errata/RHSA-2024:1082https://access.redhat.com/errata/RHSA-2024:1108https://access.redhat.com/errata/RHSA-2024:1383https://access.redhat.com/errata/RHSA-2024:2094https://access.redhat.com/security/cve/CVE-2024-0553https://bugzilla.redhat.com/show_bug.cgi?id=2258412https://gitlab.com/gnutls/gnutls/-/issues/1522https://lists.debian.org/debian-lts-announce/2024/02/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV/https://lists.fedoraproject.org/archives/list/[email protected]/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2/https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.htmlhttps://security.netapp.com/advisory/ntap-20240202-0011/
2024-01-16
Published