FlawAtlas
Search the atlas
UBUNTU-CVE-2024-13176 Moderate

UBUNTU-CVE-2024-13176

Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network connection with low latency. For that reason the severity of this vulnerability is Low. The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.

Exploit probability Not scored
Published January 20, 2025
Required by Not available
Last source change August 26, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:20.04:LTS edk2

15 explicit affected versions

Ubuntu:20.04:LTS openssl

25 explicit affected versions

Ubuntu:22.04:LTS edk2

13 explicit affected versions

Ubuntu:22.04:LTS openssl

20 explicit affected versions

Ubuntu:24.04:LTS edk2

13 explicit affected versions

Ubuntu:24.04:LTS openssl

10 explicit affected versions

Ubuntu:25.10 edk2

4 explicit affected versions

Ubuntu:26.04:LTS edk2
Ubuntu:Pro:14.04:LTS openssl

43 explicit affected versions

Ubuntu:Pro:16.04:LTS edk2

7 explicit affected versions

Ubuntu:Pro:16.04:LTS openssl

41 explicit affected versions

Ubuntu:Pro:18.04:LTS edk2

12 explicit affected versions

Ubuntu:Pro:18.04:LTS openssl

37 explicit affected versions

Ubuntu:Pro:18.04:LTS openssl1.0

23 explicit affected versions

Ubuntu:Pro:22.04:LTS nodejs

12 explicit affected versions

Ubuntu:Pro:FIPS-preview:22.04:LTS openssl

2 explicit affected versions

Ubuntu:Pro:FIPS-preview:22.04:LTS openssl-fips

1 explicit affected versions

Ubuntu:Pro:FIPS-updates:18.04:LTS openssl

22 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS openssl

12 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS openssl

7 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS openssl-fips

2 explicit affected versions

Ubuntu:Pro:FIPS-updates:24.04:LTS openssl-fips

1 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS openssl

7 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS openssl

19 explicit affected versions

Ubuntu:Pro:FIPS:18.04:LTS openssl

2 explicit affected versions

Ubuntu:Pro:FIPS:20.04:LTS openssl

2 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2024-13176

Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network connection with low latency. For that reason the severity of this vulnerability is Low. The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.

View original source

05 / REFERENCES

Further evidence