CVE-2023-5981: Debian Linux
Medium severity, CVSS 5.9. EPSS: 1.3% chance of exploitation in the next 30 days.
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 37 only; version 38 only
- GNU Gnutls: before 3.8.2 (fixed in 3.8.2)
- Red Hat Linux: version 8.0 only; version 9.0 only
Published 2023-11-28. Last modified 2026-06-17.