Executive brief
Bouncy Castle for Java, a widely used library for secure communications and data encryption, contains a flaw in its implementation of the ML-KEM (Kyber) algorithm. This vulnerability allows an attacker to potentially recover a server's long-term private encryption key by measuring the time it takes to process a large number of requests. If successful, this would allow the attacker to decrypt sensitive communications or impersonate the affected service.
Technical details
A timing side-channel vulnerability (CWE-208), known as KyberSlash, exists in Bouncy Castle for Java's ML-KEM (CRYSTALS-Kyber) implementation. The routines Poly.toMsg, Poly.compressPoly, and PolyVec.compressPolyVec perform division of secret-derived polynomial coefficients by the modulus q. Because these division operations are not constant-time on many CPU architectures, the execution time varies based on the secret values. A remote attacker who can perform a large number of decapsulations using the same long-term private key and accurately measure the timing differences can statistically recover the private key. The issue was addressed in version 1.78 by implementing constant-time division routines.
Affected products
- Legion of the Bouncy Castle Inc. BC-JAVA (bcprov) 1.73 to before 1.78
Timeline
- 2026-07-28: advisory: NVD publication date
- 2024-06-24: other: KyberSlash research published
- patched: Fixed in Bouncy Castle for Java 1.78