CVE-2023-6240
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 4, 2024
Updated: Jun 28, 2024
CWE ID 203
Summary
CVE-2023-6240 is a newly discovered vulnerability affecting the RSA decryption operation in the Linux Kernel. This Marvin vulnerability allows a network attacker to leak side-channel information during the decryption process, potentially enabling them to decrypt ciphertexts or forge signatures. The impact of this vulnerability is significant as it could limit the security of services that rely on the affected private key for encryption and signing. It is recommended that affected systems be updated with the latest Linux kernel patch to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Red Hat Enterprise Linux
- Linux Kernel
Affected Vendors
- Red Hat
- LINUX