Skip to content
CloudflareGHSA-9763-4f94-gfch

Kyber: timing side-channel (kyberslash2)

HighPublished Jan 8, 2024

### Impact On some platforms, when an attacker can time decapsulation of Kyber on forged cipher texts, they could possibly learn (parts of) the secret key. Does not apply to ephemeral usage, such as when used in the regular way in TLS. ### Patches Patched in 1.3.7. ### References - [kyberslash.cr.yp.to](https://kyberslash.cr.yp.to/)

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/cloudflare/circl
Go
< 1.3.71.3.7
Details and references

More Cloudflare advisories

All Cloudflare
Advisory
Information disclosure of Cloudflare API for low privileged users
High8.1Jan 29, 2024
Arbitrary remote code execution within `wrangler dev` Workers sandbox
High8.5Dec 29, 2023
Arbitrary remote file read in Wrangler dev server
Medium6.9Dec 29, 2023
Server-Side Request Forgery (SSRF) in Miniflare
High8.0Dec 29, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
Medium5.3Dec 12, 2023
Resource exhaustion via memory leak in tokio-boring
Medium5.3Dec 5, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.