vulnerability
Arch Linux: Information disclosure (CVE-2021-40823)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:P/I:N/A:N) | Sep 13, 2021 | Jul 11, 2025 | Mar 25, 2026 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Sep 13, 2021
Added
Jul 11, 2025
Modified
Mar 25, 2026
Description
A security has been found in matrix-js-sdk before version 12.4.1, as used by Element Web/Desktop before version 1.8.4. In certain circumstances it may be possible to trick vulnerable clients into disclosing encryption keys for messages previously sent by that client to user accounts later compromised by an attacker.
Exploiting this vulnerability to read encrypted messages requires gaining control over the recipient’s account. This requires either compromising their credentials directly or compromising their homeserver.
Thus, the greatest risk is to users who are in encrypted rooms containing malicious servers. Admins of malicious servers could attempt to impersonate their users' devices in order to spy on messages sent by vulnerable clients in that room.
Exploiting this vulnerability to read encrypted messages requires gaining control over the recipient’s account. This requires either compromising their credentials directly or compromising their homeserver.
Thus, the greatest risk is to users who are in encrypted rooms containing malicious servers. Admins of malicious servers could attempt to impersonate their users' devices in order to spy on messages sent by vulnerable clients in that room.
Solution
arch-linux-upgrade-latest
References
- CVE-2021-40823
- https://attackerkb.com/topics/CVE-2021-40823
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1944
- https://github.com/matrix-org/matrix-js-sdk/releases/tag/v12.4.1
- https://matrix.org/blog/2021/09/13/vulnerability-disclosure-key-sharing
- https://security.archlinux.org/ASA-202109-4
- https://security.archlinux.org/ASA-202109-5
- CWE-290
- EUVD-EUVD-2021-1944
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.