CVE-2023-5981: Debian Linux

Medium severity, CVSS 5.9. EPSS: 1.3% chance of exploitation in the next 30 days.

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 37 only; version 38 only
  • GNU Gnutls: before 3.8.2 (fixed in 3.8.2)
  • Red Hat Linux: version 8.0 only; version 9.0 only

Published 2023-11-28. Last modified 2026-06-17.