[CLSA-2026:1782731604] libgcrypt: Fix of CVE-2021-33560
Type:
security
Severity:
Important
Release date:
2026-06-29 11:13:40 UTC
Description:
- CVE-2013-4576: Normalize the MPIs to prevent possible side-channel attacks - CVE-2014-3591: Use ciphertext blinding for Elgamal to prevent possible side-channel attacks - CVE-2021-33560: Use of smaller K for ephemeral key in ElGamal prevent generation of weak keys - CVE-2021-40528: Add exponent blinding as well to mitigate side-channel attack on mpi_powm - tests: Add a benchmark for Elgamal
CVEs fixed:
Updated packages:
  • libgcrypt-1.5.3-14.el7.tuxcare.els1.i686.rpm
    sha:ea166b1fe2479fd4a63d0154f49279fa99a1137bf0dd87c2301ce8733843a063
  • libgcrypt-1.5.3-14.el7.tuxcare.els1.x86_64.rpm
    sha:ebd9117740604d7858ad99e38f04bc927d96f98ebe0bf95c1dfb4e6a7bf634aa
  • libgcrypt-devel-1.5.3-14.el7.tuxcare.els1.i686.rpm
    sha:ceb83272a25caee7431943783ddea3b0517d5137fa9251c0d545f108691769f2
  • libgcrypt-devel-1.5.3-14.el7.tuxcare.els1.x86_64.rpm
    sha:7bf92585d766e22ede8e37bfd5f5e041a3b9bdd527b1dd95b621c7fc87c29640
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.