CVE-2023-24532

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
GoCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
golanggo
𝑥
< 1.19.7
golanggo
1.20.0 ≤
𝑥
< 1.20.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
vulnerable
buster
postponed
golang-1.19
bookworm
1.19.8-2
fixed
bullseye
no-dsa
buster
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
ignored
trusty
ignored
golang-1.10
kinetic
dne
jammy
dne
focal
dne
bionic
needs-triage
xenial
needs-triage
trusty
ignored
golang-1.13
kinetic
ignored
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
dne
golang-1.14
kinetic
dne
jammy
dne
focal
needs-triage
bionic
dne
xenial
dne
trusty
dne
golang-1.16
kinetic
dne
jammy
dne
focal
needs-triage
bionic
needs-triage
xenial
ignored
trusty
ignored
golang-1.17
kinetic
dne
jammy
needs-triage
focal
dne
bionic
dne
xenial
ignored
trusty
ignored
golang-1.18
kinetic
dne
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
ignored
golang-1.6
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
needs-triage
trusty
ignored
golang-1.8
kinetic
dne
jammy
dne
focal
dne
bionic
needs-triage
xenial
dne
trusty
dne
golang-1.9
kinetic
dne
jammy
dne
focal
dne
bionic
needs-triage
xenial
dne
trusty
dne