Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22866

Опубликовано: 06 фев. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

A flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Considering how this function is used, this leakage is likely insufficient to recover the private key when P-256 is used in any well-known protocols.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai-tech-preview/assisted-installer-agent-rhel8Affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai-tech-preview/assisted-installer-rhel8Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9-operatorAffected
Cryostat 3cryostat-tech-preview/cryostat-ose-oauth-proxy-rhel8Fix deferred
Cryostat 3cryostat-tech-preview/cryostat-rhel8-operatorFix deferred
Cryostat 3cryostat-tech-preview/cryostat-storage-rhel8Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2344219crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

EPSS

Процентиль: 6%
0.00022
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
около 1 года назад

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 4
nvd
около 1 года назад

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 8.4
msrc
7 месяцев назад

Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

CVSS3: 4
debian
около 1 года назад

Due to the usage of a variable time instruction in the assembly implem ...

suse-cvrf
около 1 года назад

Security update for go1.23

EPSS

Процентиль: 6%
0.00022
Низкий

5.3 Medium

CVSS3