CVE-2016-0702: Canonical Ubuntu Linux

Medium severity, CVSS 5.1. EPSS: 1.9% chance of exploitation in the next 30 days.

The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-bank conflicts, aka a "CacheBleed" attack.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.3.2 (fixed in 4.3.2); from 5.0.0, before 5.7.1 (fixed in 5.7.1)
  • OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …

Published 2016-03-03. Last modified 2026-06-17.