cbcvebase.
CVE-2024-28834
published 2024-03-21

CVE-2024-28834: A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to…

PriorityP430medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
0.72%
49.7th percentile
A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiangnutls28< gnutls28 3.7.9-2+deb12u3 (bookworm)gnutls28 3.7.9-2+deb12u3 (bookworm)
msrcazl3_gnutls_3.8.3-2_on_azure_linux_3.0
msrcazl3_gnutls_3.8.3-4_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_gnutls_3.7.11-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.