CVE-2024-14041
Legion of the Bouncy Castle Inc. BC-JAVA
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that beco...
- CVSS
- 8.2
- EPSS
- 0.27% 19.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.28