Libgcrypt RSA Flaw Exposes Sensitive Data Over Network

Libgcrypt RSA Flaw Exposes Sensitive Data Over Network

First seen 1 Sep 2026, 22:29 UTC UbuntuLinuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

A timing-based side-channel vulnerability was discovered in the RSA implementation of Libgcrypt, affecting multiple versions across Ubuntu distributions. This flaw could allow remote attackers to potentially obtain sensitive information transmitted over the network. The affected versions include libgcrypt20 1.12.0-2ubuntu1.1 for Ubuntu 26.04 LTS, 1.10.3-2ubuntu0.2 for 24.04 LTS, and 1.9.4-3ubuntu3.3 for 22.04 LTS. Users are advised to perform standard system updates to mitigate the risk. The vulnerability has been assigned the identifier USN-8711-1. No active exploitation has been reported as of now, but the potential for exploitation exists. Organizations using these versions should prioritize updating to the patched versions to secure their systems.

Key Points: • Libgcrypt's RSA implementation has a critical timing-based side-channel vulnerability. • Remote attackers could exploit this flaw to access sensitive information over the network. • Users should update to the specified patched versions to mitigate risks.

Timeline

2026-09-01
Libgcrypt vulnerability disclosed
A timing-based side-channel flaw in Libgcrypt's RSA implementation was reported, affecting multiple Ubuntu versions.
Linuxsecurity
2026-09-01
Ubuntu security notice USN-8711-1 issued
Ubuntu issued a security notice regarding the Libgcrypt vulnerability, advising users to update their systems.
Ubuntu