CVE-2017-7526 describes a cache side-channel vulnerability in libgcrypt versions prior to 1.7.8, impacting RSA-1024 and potentially RSA-2048 implementations within products like Canonical, Debian, and GnuPG distributions. This high-complexity attack allows an attacker with arbitrary software execution on the target hardware to fully break RSA keys by observing timing differences during cryptographic operations. While rated Medium severity (CVSS 6.8), it has a low EPSS score and is not listed in CISA's KEV catalog, suggesting it is not widely exploited in the wild. There are no known public exploit codes (Metasploit, Nuclei, ExploitDB), though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.8CPE matchmatch criteria | cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.