<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:02:56 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-49092 — RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-49092</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RustCrypto RSA&lt;/p&gt;
&lt;p&gt;RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. There is currently no fix available. As a workaround, avoid using the RSA crate in settings where attackers are able to observe timing information, e.g. local use on a non-compromised computer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RustCrypto RSA&lt;/p&gt;
&lt;p&gt;RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. There is currently no fix available. As a workaround, avoid using the RSA crate in settings where attackers are able to observe timing information, e.g. local use on a non-compromised computer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-49092</guid>
    </item>
    <item>
      <title>GHSA-4grx-2x9w-596c — Marvin Attack: potential key recovery through timing sidechannels</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4grx-2x9w-596c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rsa&lt;/p&gt;
&lt;p&gt;The [Marvin Attack] is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.&lt;/p&gt;
&lt;p&gt;A recent survey of RSA implementations found that the Rust `rsa` crate is one of many implementations vulnerable to this attack.&lt;/p&gt;
&lt;p&gt;No fixed version is available at this time.&lt;/p&gt;
&lt;p&gt;[Marvin Attack]: https://people.redhat.com/~hkario/marvin/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rsa&lt;/p&gt;
&lt;p&gt;The [Marvin Attack] is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.&lt;/p&gt;
&lt;p&gt;A recent survey of RSA implementations found that the Rust `rsa` crate is one of many implementations vulnerable to this attack.&lt;/p&gt;
&lt;p&gt;No fixed version is available at this time.&lt;/p&gt;
&lt;p&gt;[Marvin Attack]: https://people.redhat.com/~hkario/marvin/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4grx-2x9w-596c</guid>
    </item>
  </channel>
</rss>
