Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-0495

19
FAUCET Score

CVE-2018-0495 describes a memory-cache side-channel vulnerability in Libgcrypt versions before 1.7.10 and 1.8.x before 1.8.3, impacting products like Canonical, Debian, GnuPG, Oracle, and Red Hat. This flaw, known as the Return Of the Hidden Number Problem (ROHNP), allows an attacker with local or same-physical-host virtual machine access to potentially discover ECDSA keys by observing side-channel leakage during the signing process. Rated Medium severity (CVSS 4.7), it requires high attack complexity and low privileges, with the primary impact being confidentiality compromise. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.7.10CPE matchmatch criteria
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*
>= 1.8.0, < 1.8.3CPE matchmatch criteria
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.0

4.7MEDIUM

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.89%
Probability of exploitation in next 30 days
EPSS Percentile
55.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0089 is in the 90th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (32)

oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services Apache HTTP Server 2.4.29 SP2
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services Apache HTTP Server 2.4.29 SP2Fixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.29-40.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-openssl-1:1.0.2n-15.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.29-40.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.0.2n-15.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-34/ansible-tower-memcached:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-35/ansible-tower-memcached:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl-1:1.0.2k-16.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: nspr-0:4.21.0-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: nss-0:3.44.0-4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: nss-softokn-0:3.44.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: nss-util-0:3.44.0-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: nss-softokn-0:3.28.3-9.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: nss-softokn-0:3.28.3-9.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.5 Extended Update SupportFixed in: nss-softokn-0:3.36.0-6.el7_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: nss-softokn-0:3.36.0-6.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: nss-softokn-0:3.28.3-9.el7_4
View patch
redhatno patchvia redhat_api
Product: Red Hat JBoss Web Server 3Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: nss
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openssl097a
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: nss
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl
redhatend of lifevia redhat_api
Product: CloudForms Management Engine 5Fixed in: libtomcrypt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl098e
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: OVMF
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl098e

Vendor Advisories (1)

redhatCVE-2018-0495Moderate

ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries

Jun 13, 2018

References

access.redhat.com / errata/RHSA-2018:3221
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3505
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1296
access.redhat.com / errata/RHSA-2019:1297
access.redhat.com / errata/RHSA-2019:1543
access.redhat.com / errata/RHSA-2019:2237
dev.gnupg.org / T4011
PatchVendor Advisory
git.gnupg.org / cgi-bin/gitweb.cgi
lists.debian.org / debian-lts-announce/2018/06/msg00013.html
Mailing ListThird Party Advisory
lists.gnupg.org / pipermail/gnupg-announce/2018q2/000426.html
Vendor Advisory
usn.ubuntu.com / 3689-1
Third Party Advisory
usn.ubuntu.com / 3689-2
Third Party Advisory
usn.ubuntu.com / 3692-1
Third Party Advisory
usn.ubuntu.com / 3692-2
Third Party Advisory
usn.ubuntu.com / 3850-1
Third Party Advisory
usn.ubuntu.com / 3850-2
Third Party Advisory
debian.org / security/2018/dsa-4231
Third Party Advisory
nccgroup.trust / us/our-research/technical-advisory-return-of-the-hidden-number-problem
ExploitThird Party Advisory
oracle.com / technetwork/security-advisory/cpuapr2019-5072813.html
PatchThird Party Advisory
securitytracker.com / id/1041144
Third Party AdvisoryVDB Entry
securitytracker.com / id/1041147
Third Party AdvisoryVDB Entry