CVE-2024-2236: Red Hat Enterprise Linux 10
Medium severity, CVSS 5.9. EPSS: 1.1% chance of exploitation in the next 30 days.
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 0:1.10.0-11.el9 (fixed in 0:1.10.0-11.el9)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:1.10.0-10.el9_2.1 (fixed in 0:1.10.0-10.el9_2.1)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:1.10.0-10.el9_4.1 (fixed in 0:1.10.0-10.el9_4.1)
Published 2024-03-06. Last modified 2026-06-17.