Marvin Attack: potential key recovery through timing sidechannels
Moderate severity
GitHub Reviewed
Published
Nov 28, 2023
to the GitHub Advisory Database
•
Updated Dec 14, 2023
Description
Published to the GitHub Advisory Database
Nov 28, 2023
Reviewed
Nov 28, 2023
Last updated
Dec 14, 2023
The Marvin Attack is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.
A recent survey of RSA implementations found that the Rust
rsa
crate is one of many implementations vulnerable to this attack.No fixed version is available at this time.
References