Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-50237

Опубликовано: 28 июл. 2025
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.

A flaw was found in ed25519-dalek. The Keypair implementation allows an attacker to compute a private key by observing signatures generated with corresponding public keys. This public key signing function oracle attack does not require authentication. An unauthenticated attacker can extract the private key by observing repeated signatures. This compromise of the key can result in unauthorized data signing.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/log-file-metric-exporter-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Not affected
Red Hat Enterprise Linux 10rust-sequoia-sqNot affected
Red Hat Enterprise Linux 10rust-sequoia-sqvNot affected
Red Hat Enterprise Linux 10trustee-guest-componentsNot affected
Red Hat Enterprise Linux 9trustee-guest-componentsNot affected
Red Hat OpenShift Container Platform 4kata-containersNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2383801ed25519-dalek: ed25519-dalek: Private Key Extraction Vulnerability

EPSS

Процентиль: 0%
0.00004
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
6 месяцев назад

The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.

CVSS3: 5.9
nvd
6 месяцев назад

The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.

CVSS3: 5.9
debian
6 месяцев назад

The ed25519-dalek crate before 2 for Rust allows a double public key s ...

CVSS3: 5.9
github
больше 2 лет назад

`ed25519-dalek` Double Public Key Signing Function Oracle Attack

EPSS

Процентиль: 0%
0.00004
Низкий

5.9 Medium

CVSS3