{"id":"CVE-2024-14041","summary":"ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)","details":"In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.","modified":"2026-08-28T14:32:47.953563Z","published":"2026-07-28T08:05:35.310Z","database_specific":{"cwe_ids":["CWE-208"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14041.json","cna_assigner":"bcorg"},"references":[{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14041.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-java/wiki/CVE-2024-14041"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-14041"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/5adb2c5c5b462a332b01a012bea0784b40b904e5"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"ARTICLE","url":"https://kyberslash.cr.yp.to/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"9032821b326fba9fec7528899dfffa79f9f19aef"},{"fixed":"30c6cc60ef5aa9062a083a8cea3e5c4f96d91a2a"},{"fixed":"1590247178f2280defa36421475f015175dfbe9e"},{"fixed":"5adb2c5c5b462a332b01a012bea0784b40b904e5"}],"database_specific":{"cpe":"cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.73"},{"fixed":"1.78"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["r1rv77","r1rv76","r1rv75","r1rv74","r1rv73"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-14041.json","vanir_signatures_modified":"2026-08-28T14:32:47Z","vanir_signatures":[{"source":"https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e","target":{"file":"core/src/main/java/org/bouncycastle/pqc/crypto/crystals/kyber/PolyVec.java","function":"compressPolyVec"},"deprecated":false,"digest":{"function_hash":"67514196186535623956027326555111153015","length":2136},"id":"CVE-2024-14041-43905242","signature_type":"Function","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/30c6cc60ef5aa9062a083a8cea3e5c4f96d91a2a","target":{"file":"prov/src/test/jdk1.1/org/bouncycastle/jce/provider/test/CertTest.java","function":"checkCreation3"},"deprecated":false,"digest":{"function_hash":"211490410986357392843513459334772224186","length":4101},"id":"CVE-2024-14041-59a1653a"},{"deprecated":false,"digest":{"line_hashes":["285309072946473922736525436005230105480","158364824053661404594680273245529793255","87428423338063994161394849297751535661","176552572181804896530952856922967093020","332234115540556241653046077794891667337","61166050518896324944301833502322671953","199751680947270425684130123626402723834","177360621385029187797868509247609117433","131239377051978341044523770609896877570","285309072946473922736525436005230105480","136357653485727919598694156357465815847","18852002172696229580617966175289469367","221240042311307129454595821155209147039","182419377277279813995869352182868515124","305779552862874156941014770214700723193","294519606160985195852369611990340723803","154185068027426882747252552713743705868","110410282017318234177191870774981765976","115335819967310170565523975062483315917"],"threshold":0.9},"id":"CVE-2024-14041-828ac487","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e","target":{"file":"core/src/main/java/org/bouncycastle/pqc/crypto/crystals/kyber/Poly.java"}},{"target":{"file":"core/src/main/jdk1.1/org/bouncycastle/util/BigIntegers.java"},"deprecated":false,"digest":{"line_hashes":["300603618156872282375712415734111285725","276034351500733570581841163074868711431","77770816554066311444805528877586846264"],"threshold":0.9},"id":"CVE-2024-14041-8f72cc80","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/30c6cc60ef5aa9062a083a8cea3e5c4f96d91a2a"},{"signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e","target":{"file":"core/src/main/java/org/bouncycastle/pqc/crypto/crystals/kyber/PolyVec.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["2372762903220393617120758185767402464","183373273085814397142607117562412454133","23276957152853511022955731387174268554","279544597995821337777410319730727172812","278063050059133359865235673455220611520","108730025621839624361402839626844212035","334561547610358596762863707914009901817","272693499711583346094548595561361346708","215135229624861914105366099584029681955","92408522477349729233592585718496282303","21431229162468595104984351366949296004","51835296394358387800365056118657532466","23276957152853511022955731387174268554","289673713242716907240527678571501273859","42052470650349429280720564520040444393","277955579668020855687591396668372894474","75584877325301355481846436772006452824","293249165405069920256297154130676556901","55148653194822269364096337465364479650","316489513901185405811827502529973088809"]},"id":"CVE-2024-14041-aad7dc35","signature_type":"Line"},{"target":{"file":"core/src/main/java/org/bouncycastle/pqc/crypto/crystals/kyber/Poly.java"},"deprecated":false,"digest":{"line_hashes":["286376463245354548357902323580759001430","298596219661853809754094638421815551468","86511827192358664569663762045092878516","249165803340656714415839407338572155626","213853547471748558126346309936299087746","307039920982004594872767175734998319578","81604809457332476433969030829097127847","235006413645156618283949117138269880698","99076741616423411559167003932403736905","231563780766339172933436551728299998704","21297216777339819764100345618968274193","59121718067267294460971331857893910627"],"threshold":0.9},"id":"CVE-2024-14041-b4752558","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/5adb2c5c5b462a332b01a012bea0784b40b904e5"},{"target":{"file":"prov/src/test/jdk1.1/org/bouncycastle/jce/provider/test/CertTest.java"},"deprecated":false,"digest":{"line_hashes":["170389307891483721281926286472113815870","73724035249486516467607034760695252714","260917414265667472255462271410390583015","193327030186129717743495799486333488757","236831945343289876206774171157129303395","230929008786997747382832711614224342277","199832741301999372182660746343191085795"],"threshold":0.9},"id":"CVE-2024-14041-b4a175c2","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/30c6cc60ef5aa9062a083a8cea3e5c4f96d91a2a"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/5adb2c5c5b462a332b01a012bea0784b40b904e5","target":{"file":"core/src/main/java/org/bouncycastle/pqc/crypto/crystals/kyber/Poly.java","function":"toMsg"},"deprecated":false,"digest":{"function_hash":"55937126234282289393387437714282519879","length":446},"id":"CVE-2024-14041-bf82a73d"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e","target":{"file":"core/src/main/java/org/bouncycastle/pqc/crypto/crystals/kyber/Poly.java","function":"compressPoly"},"deprecated":false,"digest":{"function_hash":"2977403301203002721212481260907335455","length":1541},"id":"CVE-2024-14041-cf1b266d"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber"}]}