CVE-2024-2236: Red Hat Enterprise Linux 10

Medium severity, CVSS 5.9. EPSS: 1.1% chance of exploitation in the next 30 days.

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 0:1.10.0-11.el9 (fixed in 0:1.10.0-11.el9)
  • Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:1.10.0-10.el9_2.1 (fixed in 0:1.10.0-10.el9_2.1)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:1.10.0-10.el9_4.1 (fixed in 0:1.10.0-10.el9_4.1)

Published 2024-03-06. Last modified 2026-06-17.