CVE-2017-7526 MEDIUM

CVE-2017-7526

Vendor Gnupg
Product libgcrypt
Weakness CWE-200 · Info exposure
Published July 26, 2018
Last update December 17, 2025

CVSS base score

6.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.

Key dates

02Disclosure timeline

July 26, 2018 CVE published
December 17, 2025 Record updated