Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9hv-hpm4-hj6x

Опубликовано: 25 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.9

Описание

CIRCL has an incorrect calculation in secp384r1 CombinedMult

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected.

The bug was fixed in v1.6.3.

Пакеты

Наименование

github.com/cloudflare/circl

go
Затронутые версииВерсия исправления

< 1.6.3

1.6.3

EPSS

Процентиль: 34%
0.00397
Низкий

2.9 Low

CVSS4

Дефекты

CWE-682

Связанные уязвимости

CVSS3: 9.8
ubuntu
7 месяцев назад

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

CVSS3: 9.8
nvd
7 месяцев назад

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

suse-cvrf
3 месяца назад

Security update for enc

suse-cvrf
3 месяца назад

Security update for go-sendxmpp

suse-cvrf
4 месяца назад

Security update for git-bug

EPSS

Процентиль: 34%
0.00397
Низкий

2.9 Low

CVSS4

Дефекты

CWE-682