{"id":"GHSA-4grx-2x9w-596c","summary":"Marvin Attack: potential key recovery through timing sidechannels","details":"The [Marvin Attack] is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.\n\nA recent survey of RSA implementations found that the Rust `rsa` crate is one of many implementations vulnerable to this attack.\n\nNo fixed version is available at this time.\n\n[Marvin Attack]: https://people.redhat.com/~hkario/marvin/","aliases":["CVE-2023-49092","GHSA-c38w-74pg-36hr","RUSTSEC-2023-0071"],"modified":"2026-07-17T21:12:45.068888728Z","published":"2023-11-28T23:28:25Z","database_specific":{"github_reviewed_at":"2023-11-28T23:28:25Z","nvd_published_at":null,"cwe_ids":["CWE-385"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/RustCrypto/RSA/security/advisories/GHSA-c38w-74pg-36hr"},{"type":"WEB","url":"https://github.com/RustCrypto/RSA/issues/19#issuecomment-1822995643"},{"type":"WEB","url":"https://github.com/RustCrypto/RSA/issues/626"},{"type":"PACKAGE","url":"https://github.com/RustCrypto/RSA"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0071.html"}],"affected":[{"package":{"name":"rsa","ecosystem":"crates.io","purl":"pkg:cargo/rsa"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.9.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-4grx-2x9w-596c/GHSA-4grx-2x9w-596c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}