CVE-2023-52323
Publication date 5 January 2024
Last updated 26 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| pycryptodome | 24.04 LTS noble |
Not affected
|
| 22.04 LTS jammy |
Fixed 3.11.0+dfsg1-3ubuntu0.1
|
|
| 20.04 LTS focal | Ignored | |
| 18.04 LTS bionic | Ignored end of standard support | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release |
Notes
mdeslaur
Ubuntu 20.04 LTS and older contain a substantially older codebase which would require major intrusive changes to remediate all side-channel attacks. Due to the high risk of regressions, we will not be fixing this issue in focal and older. If this issue is critical in your environment, we recommend migrating to a more recent version of Ubuntu.
Patch details
| Package | Patch details |
|---|---|
| pycryptodome |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.9 · Medium
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
References
Related Ubuntu Security Notices (USN)
- USN-6595-1
- PyCryptodome vulnerability
- 23 January 2024