Junglewise Threat Intelligence

CVE-2024-14041: Bouncy Castle for Java timing side-channel in ML-KEM

CVE-2024-14041 · Severity: info · CVSS 8.2 · Published 2026-07-28

Technologies: Legion of the Bouncy Castle Inc. BC-JAVA (bcprov). Vendors: Legion of the Bouncy Castle Inc..

Executive brief

Bouncy Castle for Java, a widely used library for secure communications and data encryption, contains a flaw in its implementation of the ML-KEM (Kyber) algorithm. This vulnerability allows an attacker to potentially recover a server's long-term private encryption key by measuring the time it takes to process a large number of requests. If successful, this would allow the attacker to decrypt sensitive communications or impersonate the affected service.

Technical details

A timing side-channel vulnerability (CWE-208), known as KyberSlash, exists in Bouncy Castle for Java's ML-KEM (CRYSTALS-Kyber) implementation. The routines Poly.toMsg, Poly.compressPoly, and PolyVec.compressPolyVec perform division of secret-derived polynomial coefficients by the modulus q. Because these division operations are not constant-time on many CPU architectures, the execution time varies based on the secret values. A remote attacker who can perform a large number of decapsulations using the same long-term private key and accurately measure the timing differences can statistically recover the private key. The issue was addressed in version 1.78 by implementing constant-time division routines.

Affected products

  • Legion of the Bouncy Castle Inc. BC-JAVA (bcprov) 1.73 to before 1.78

Timeline

  • 2026-07-28: advisory: NVD publication date
  • 2024-06-24: other: KyberSlash research published
  • patched: Fixed in Bouncy Castle for Java 1.78

References