{"id":"CVE-2023-5981","details":"A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.","modified":"2026-03-20T12:33:51.931194Z","published":"2023-11-28T12:15:07.040Z","related":["ALSA-2024:0155","ALSA-2024:0533","ALSA-2024:0627","MGASA-2024-0008","SUSE-SU-2023:4952-1","SUSE-SU-2023:4983-1","SUSE-SU-2023:4986-1","SUSE-SU-2024:0860-1","SUSE-SU-2024:1179-1","openSUSE-SU-2024:13444-1"],"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/01/19/3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/11/msg00016.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:0319"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2094"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:0155"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:0399"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:0451"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:0533"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:1383"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2023-5981"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2248445"},{"type":"REPORT","url":"https://gnutls.org/security-new.html#GNUTLS-SA-2023-10-23"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnutls/gnutls","events":[{"introduced":"0"},{"last_affected":"eccf559a7f615e0cee95459973e4fb85809af98c"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"1.5.0"}]}}],"versions":["gnutls-0-0-7","gnutls-0-1-0-srp","gnutls-0_1_2","gnutls0-0-4","gnutls0-0-5","gnutls0-0-6","gnutls_0_1_4","gnutls_0_1_9","gnutls_0_2_0","gnutls_0_2_1","gnutls_0_2_10","gnutls_0_2_11","gnutls_0_2_2","gnutls_0_2_3","gnutls_0_2_4","gnutls_0_2_9","gnutls_0_2_90","gnutls_0_2_91","gnutls_0_3_0","gnutls_0_3_1","gnutls_0_3_2","gnutls_0_3_90","gnutls_0_3_91","gnutls_0_3_92","gnutls_0_4_0","gnutls_0_4_1","gnutls_0_4_2","gnutls_0_4_3","gnutls_0_4_with_libtasn1","gnutls_0_5_0","gnutls_0_5_1","gnutls_0_5_10","gnutls_0_5_11","gnutls_0_5_4","gnutls_0_5_5","gnutls_0_5_6","gnutls_0_5_7","gnutls_0_5_8","gnutls_0_5_9","gnutls_0_5_x_before_export_ciphersuites","gnutls_0_5_x_before_int_fixes","gnutls_0_5_x_before_types_change","gnutls_0_5_x_with_export_ciphersuites","gnutls_0_6_0","gnutls_0_8_0","gnutls_0_8_1","gnutls_0_9_1","gnutls_0_9_2","gnutls_0_9_3","gnutls_0_9_4","gnutls_0_9_5","gnutls_0_9_6","gnutls_0_9_7","gnutls_0_9_8","gnutls_0_9_90","gnutls_0_9_91","gnutls_0_9_92","gnutls_0_9_93","gnutls_0_9_94","gnutls_0_9_95","gnutls_0_9_96","gnutls_0_9_97","gnutls_0_9_98","gnutls_0_9_99","gnutls_1_0_0","gnutls_1_0_20","gnutls_1_0_21","gnutls_1_0_22","gnutls_1_0_23","gnutls_1_0_24","gnutls_1_0_25","gnutls_1_1_0","gnutls_1_1_1","gnutls_1_1_10","gnutls_1_1_11","gnutls_1_1_12","gnutls_1_1_13","gnutls_1_1_14","gnutls_1_1_15","gnutls_1_1_16","gnutls_1_1_17","gnutls_1_1_18","gnutls_1_1_19","gnutls_1_1_2","gnutls_1_1_20","gnutls_1_1_21","gnutls_1_1_22","gnutls_1_1_23","gnutls_1_1_3","gnutls_1_1_4","gnutls_1_1_5","gnutls_1_1_6","gnutls_1_1_7","gnutls_1_1_7_pre0","gnutls_1_1_8","gnutls_1_1_9","gnutls_1_2_0","gnutls_1_2_1","gnutls_1_2_10","gnutls_1_2_11","gnutls_1_2_2","gnutls_1_2_3","gnutls_1_2_4","gnutls_1_2_5","gnutls_1_2_6","gnutls_1_2_7","gnutls_1_2_8","gnutls_1_2_9","gnutls_1_3_0","gnutls_1_3_1","gnutls_1_3_2","gnutls_1_3_3","gnutls_1_3_4","gnutls_1_3_5","gnutls_1_4_0","gnutls_1_4_1","gnutls_1_4_2","gnutls_1_5_0"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"37"}]},{"events":[{"introduced":"0"},{"last_affected":"38"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-5981.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}