Security

GnuPG crypto library cracked, look for patches

Boffins bust libgcrypt via side-channel


Linux users need to check out their distributions to see if a nasty bug in libgcrypt20 has been patched.

The software fix, which has landed in Debian and Ubuntu, addresses a side-channel attack published last week.

The researchers published their work at the International Association for Cryptologic Research's e-print archive last week. The paper was authored by Daniel Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal and Yuval Yarom (who hail variously from the Technical University of Eindhoven, the University of Illinois, the University of Pennsylvania, the University of Maryland, and the University of Adelaide).

What they found is that the libgcrypt library used what's called “sliding windows”, a method for carrying out the mathematics of cryptography – but one that's known to leak data.

The researchers looked at the left-to-right sliding window calculation in libgcrypt, in which the sliding window data leak was tolerated because it was believed only part of a key was recoverable (40 percent of bits in a four-bit sliding window; 33 percent in a five-bit sliding window).

What they found was an unpleasant surprise: a complete break of the library's RSA-1024: “We show for the first time that the direction of the encoding matters: the pattern of squarings and multiplications in left-to-right sliding windows leaks significantly more information about the exponent than right-to-left”.

To get at the processing, the researchers also needed to carry out a side-channel attack, specifically a flush+reload cache-timing attack “that monitors the target's cache access patterns”.

Debian users can update the library here; Ubuntu has it here. ®

Send us news
29 Comments

After delay due to xz, Ubuntu 24.04 'Noble Numbat' belatedly hits beta

Kernel 6.8, GNOME 46, and more apps in Snap packages

Qt Ubuntu 24.04 betas show that there's room to innovate

Hot on the heels of Ubuntu Noble beta come the betas of the Qt-based remixes, with some interesting differences

Debian spices up APT package manager with a dash of color, squishes ancient bug

2.9 gives a taste of what's to come

Canonical cracks down on crypto cons following Snap Store scam spree

In happier news, Ubuntu Pro extended support now goes up to 12 years

TrueNAS CORE 13 is the end of the FreeBSD version

Debian-based TrueNAS SCALE is the future primary focus

Fresh version of Windows user-friendly Zorin OS arrives to tempt the Linux-wary

Adding extra shine to Ubuntu Jammy… with the lightweight edition to follow

Raspberry Pi OS 5.2 is here, with pleasant tweaks to Wayland-based desktop

Kernel 6.6 and small refinements, plus less visible, but meaningful adjustments

Ubuntu, Kubuntu, openSUSE to get better installation

Fedora, though, won't – until at least the version after next

KDE 6 misses boat to make it into Kubuntu 24.04

'Noble Numbat' users will face a major post-install upgrade, which isn't ideal

SparkyLinux harbors a flamboyant array of desktops

Both stable and rolling releases, Pi versions, and some very unusual customizations

Mint freshens up its Linux garden for Ubuntu and Debian fans

One version's edgier than the other

Ubuntu for Arm64 laptops (plus RISC kit)

Did you know there's an Asahi flavored Ubuntu? And Debian, too