While working on PowerPC support (D490 D491 D492 D493) I noticed that the C implementation of AES is vulnerable to side-channel attacks. (described below)
My patches are not vulnerable to this, but users of libgcrypt on PowerPC *before* my patches are.