CVE-2023-6240

Updated: 2026-02-27 00:46:05.251157

Description:

A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 6.5 MEDIUM Ignored 2025-09-23 11:44:46 Deprioritize: the vulnerable code path is RSA private-key decryption inside the kernel, but Linux do...
CentOS 6 ELS kernel 2.6.32 6.5 MEDIUM Ignored 2024-04-18 14:10:58 Ignored due to low severity
CentOS 7 ELS kernel 3.10.0 6.5 MEDIUM Ignored 2024-06-24 11:25:01 Ignored due to low severity
CentOS 8.4 ELS kernel 4.18.0 6.5 MEDIUM Ignored 2024-06-24 11:25:01 Ignored due to low severity
CentOS 8.5 ELS kernel 4.18.0 6.5 MEDIUM Ignored 2024-06-24 11:25:01 Ignored due to low severity
CentOS Stream 8 ELS kernel 4.18.0 6.5 MEDIUM Already Fixed 2024-06-09 14:19:20
CloudLinux 6 ELS kernel 2.6.32 6.5 MEDIUM Ignored 2024-06-24 10:15:12 Ignored due to low severity
Oracle Linux 6 ELS kernel 2.6.32 6.5 MEDIUM Ignored 2024-04-18 14:10:58 Ignored due to low severity
Ubuntu 16.04 ELS linux-hwe 4.15.0 6.5 MEDIUM Ignored 2024-04-18 14:10:56 Ignored due to low severity
Ubuntu 16.04 ELS linux 4.4.0 6.5 MEDIUM Ignored 2024-04-18 14:10:56 Ignored due to low severity
Total: 11