The vendor explicitly identifies these products as affected by this CVE.
- bouncycastle as a component of Red Hat Integration Camel Quarkus 1
- bouncycastle as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- bouncycastle as a component of Red Hat OpenShift Application Runtimes
- bouncycastle as a component of Red Hat Single Sign-On 7
- bouncycastle as a component of Red Hat support for Spring Boot
- Summary
- A flaw was found in bouncycastle. A timing issue within the EC math library can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
