FlawAtlas
Search the atlas
UBUNTU-CVE-2022-4304 Moderate

UBUNTU-CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

Exploit probability Not scored
Published February 7, 2023
Required by Not available
Last source change August 26, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS openssl

25 explicit affected versions

Ubuntu:20.04:LTS edk2

15 explicit affected versions

Ubuntu:20.04:LTS openssl

18 explicit affected versions

Ubuntu:22.04:LTS edk2

13 explicit affected versions

Ubuntu:22.04:LTS nodejs

7 explicit affected versions

Ubuntu:22.04:LTS openssl

10 explicit affected versions

Ubuntu:Pro:14.04:LTS openssl

43 explicit affected versions

Ubuntu:Pro:16.04:LTS edk2

7 explicit affected versions

Ubuntu:Pro:16.04:LTS openssl

41 explicit affected versions

Ubuntu:Pro:18.04:LTS edk2

12 explicit affected versions

Ubuntu:Pro:18.04:LTS openssl1.0

23 explicit affected versions

Ubuntu:Pro:FIPS-updates:18.04:LTS openssl

12 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS openssl

6 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS openssl

7 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS openssl

19 explicit affected versions

Ubuntu:Pro:FIPS:18.04:LTS openssl

2 explicit affected versions

Ubuntu:Pro:FIPS:20.04:LTS openssl

2 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

View original source

05 / REFERENCES

Further evidence