RustCrypto / RSA

RSA implementation in pure Rust
Apache License 2.0
536 stars 146 forks source link

Marvin Attack: potential key recovery through timing sidechannels #408

Closed ananduremanan closed 7 months ago

ananduremanan commented 7 months ago

I got the error

The Marvin Attack is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.

A recent survey of RSA implementations found that the Rust rsa crate is one of many implementations vulnerable to this attack.

No fixed version is available at this time.

as a Dependabot alert in my github repository . What Does this means?

tarcieri commented 7 months ago

See #19.

As noted, there is currently no fix available. It's being worked on in #394.