← Back to CVE List

CVE-2019-12904

Published: 2019-06-20T00:15Z
Last Modified: 2024-11-21T04:23Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack > MITRE Terms of Use apply – see LICENSE‑MITRE.txt