What is CVE-2026-16459?
CVE-2026-16459 is a padding oracle vulnerability in Oberon microsystem AG's Oberon PSA Crypto library, affecting all versions from 1.0.0 prior to 2.1.1. It allows attackers to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations. Upgrading to version 2.1.1 or later is recommended.
Azərbaycanca: CVE-2026-16459, Oberon microsystem AG-nin Oberon PSA Crypto kitabxanasında aşkar edilmiş padding oracle zəifliyidir. Bu, 1.0.0-dan 2.1.1-ə qədər bütün versiyalara təsir edir və təcavüzkara RSA PKCS#1 v1.5 deşifrə əməliyyatlarının zaman ölçmələri vasitəsilə plaintext-ləri bərpa etməyə imkan verir. Kitabxananı 2.1.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
FAQ2
What versions of the Oberon PSA Crypto library are affected by CVE-2026-16459?
The vulnerability affects all versions from 1.0.0 up to, but not including, version 2.1.1.
How can an attacker exploit the weakness in RSA PKCS#1 v1.5 operations described in this CVE?
An attacker can recover plaintexts through a padding oracle attack by performing timing measurements of RSA PKCS#1 v1.5 decrypt operations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.