CVE-2024-58262

EUVD-2024-54823
The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.9 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
mitreCNA
2.9 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
dalekcurve25519-dalek
𝑥
< 4.1.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rust-curve25519-dalek
forky
4.2.0+dfsg-1
fixed
sid
4.2.0+dfsg-1
fixed
trixie
4.1.3+20240618+dfsg-9
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rust-curve25519-dalek
jammy
dne
noble
dne
plucky
not-affected