A vulnerability classified as problematic has been found in Legion of the Bouncy Castle BC-JAVA up to 1.77. This affects the function
Poly.toMsg/Poly.compressPoly/PolyVec.compressPolyVec of the component ML-KEM. This manipulation causes observable timing discrepancy.
The identification of this vulnerability is CVE-2024-14041. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.