CVE-2013-4242: Canonical Ubuntu Linux

Low severity, CVSS 1.9. EPSS: 0.5% chance of exploitation in the next 30 days.

GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.04 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Gnupg Gnupg: up to and including 1.4.13; version 0.0.0 only; version 0.2.15 only; version 0.2.16 only; version 0.2.17 only; version 0.2.18 only; …
  • Gnupg Libgcrypt: up to and including 1.5.2; version 1.4.0 only; version 1.4.3 only; version 1.4.4 only; version 1.4.5 only; version 1.4.6 only; …
  • Opensuse Opensuse: version 12.2 only; version 12.3 only

Published 2013-08-19. Last modified 2026-06-16.