CVE-2024-45191

Name
CVE-2024-45191
Description
An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/
https://gitlab.matrix.org/matrix-org/olm/
https://news.ycombinator.com/item?id=41249371
https://gitlab.matrix.org/matrix-org/olm/-/commit/6d4b5b07887821a95b144091c8497d09d377f985

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:matrix:olm:*:*:*:*:*:*:*:* olm >= 0 <= 3.2.16

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
olm edge-community 3.2.16-r1 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
olm 3.20-community 3.2.16-r1 Bart Ribbers <bribbers@disroot.org> possibly vulnerable