CVE-2023-24532

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
golanggo
𝑥
< 1.19.7
golanggo
1.20.0 ≤
𝑥
< 1.20.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
vulnerable
buster
postponed
golang-1.19
bookworm
1.19.8-2
fixed
bullseye
no-dsa
buster
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
bionic
dne
focal
dne
jammy
dne
kinetic
dne
trusty
ignored
xenial
ignored
golang-1.10
bionic
needs-triage
focal
dne
jammy
dne
kinetic
dne
trusty
ignored
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
kinetic
ignored
trusty
dne
xenial
needs-triage
golang-1.14
bionic
dne
focal
needs-triage
jammy
dne
kinetic
dne
trusty
dne
xenial
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
kinetic
dne
trusty
ignored
xenial
ignored
golang-1.17
bionic
dne
focal
dne
jammy
needs-triage
kinetic
dne
trusty
ignored
xenial
ignored
golang-1.18
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
kinetic
dne
trusty
ignored
xenial
needs-triage
golang-1.6
bionic
dne
focal
dne
jammy
dne
kinetic
dne
trusty
ignored
xenial
needs-triage
golang-1.8
bionic
needs-triage
focal
dne
jammy
dne
kinetic
dne
trusty
dne
xenial
dne
golang-1.9
bionic
needs-triage
focal
dne
jammy
dne
kinetic
dne
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
container-suseconnect
suse enterprise server 15 SP3
2.4.0-150000.4.24.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
golang
RHEL 9
0:1.19.9-2.el9_2
fixed
golang-bin
RHEL 9
0:1.19.9-2.el9_2
fixed
golang-docs
RHEL 9
0:1.19.9-2.el9_2
fixed
golang-misc
RHEL 9
0:1.19.9-2.el9_2
fixed
golang-race
RHEL 9
0:1.19.9-2.el9_2
fixed
golang-src
RHEL 9
0:1.19.9-2.el9_2
fixed
golang-tests
RHEL 9
0:1.19.9-2.el9_2
fixed