We investigate a known plaintext attack on RC5 based on correlations. Compared with the best previous known-plaintext attack
on RC5-32, a linear cryptanalysis by Borst, Preneel, and Vandewalle, our attack applies to a larger number of rounds. RC5-32
with r rounds can be broken with a success probability of 90% by using 26.14r+2.27 plaintexts. Therefore, our attack can break RC5-32 with 10 rounds (20 half-rounds) with 263.67 plaintexts with a probability of 90%. With a success probability of 30%, our attack can break RC5-32 with 21 halfrounds by
using 263.07 plaintexts.