What is CVE-2024-14041?
CVE-2024-14041 is a vulnerability in Bouncy Castle for Java versions 1.73 to 1.77 where ML-KEM (CRYSTALS-Kyber) routines divide secret-derived coefficients by modulus q, affecting Poly.toMsg and compression routines. Attackers could potentially recover decrypted messages. Affected users must upgrade to version 1.78 immediately.
Azərbaycanca: CVE-2024-14041, Bouncy Castle for Java-nın 1.73-dən 1.77-dək versiyalarında ML-KEM (CRYSTALS-Kyber) rutinlərində gizli məlumatların modul q ilə bölünməsi zəifliyidir. Bu, hücumçulara deşifrə mesajlarını oxumağa imkan yarada bilər. Təsirə məruz qalan sistemlərin dərhal 1.78 versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ2
Which versions of Bouncy Castle are affected by CVE-2024-14041?
This vulnerability affects Bouncy Castle for Java versions 1.73 to 1.77.
What is the recommended version to remediate this vulnerability?
Users are advised to upgrade to Bouncy Castle version 1.78 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.