A vulnerability classified as problematic has been found in Legion of the Bouncy Castle BC-JAVA up to 1.77. This affects the function Poly.toMsg/Poly.compressPoly/PolyVec.compressPolyVec of the component ML-KEM. This manipulation causes observable timing discrepancy.

The identification of this vulnerability is CVE-2024-14041. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.