Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-42770

Опубликовано: 09 июн. 2026
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 3.7

Описание

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts. When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared. A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leak...

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

not-affected

3.0+ only
esm-apps/bionic

not-affected

3.0+ only
esm-infra/focal

not-affected

3.0+ only
jammy

not-affected

3.0+ only
noble

needs-triage

questing

ignored

end of life, was needs-triage
resolute

needs-triage

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system openssl
esm-apps-legacy/xenial

not-affected

3.0+ only
esm-apps/bionic

not-affected

3.0+ only
esm-apps/focal

not-affected

uses system openssl
esm-apps/jammy

needed

esm-apps/noble

not-affected

uses system openssl
esm-apps/resolute

not-affected

uses system openssl
esm-infra-legacy/trusty

not-affected

uses system openssl
jammy

needed

noble

not-affected

uses system openssl

Показывать по

РелизСтатусПримечание
devel

not-affected

3.5.5-1ubuntu4
esm-infra-legacy/trusty

not-affected

3.0+ only
esm-infra-legacy/xenial

not-affected

3.0+ only
esm-infra/bionic

not-affected

3.0+ only
esm-infra/focal

not-affected

3.0+ only
fips-preview/jammy

needed

fips-updates/bionic

not-affected

3.0+ only
fips-updates/focal

not-affected

3.0+ only
fips-updates/jammy

released

3.0.2-0ubuntu1.25+Fips1
fips-updates/xenial

not-affected

3.0+ only

Показывать по

РелизСтатусПримечание
devel

DNE

fips-preview/jammy

needs-triage

fips-updates/jammy

needs-triage

fips-updates/noble

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

3.0+ only
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 37%
0.00455
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
около 2 месяцев назад

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts. When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared. A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leak...

CVSS3: 3.7
nvd
около 2 месяцев назад

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts. When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared. A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leak

CVSS3: 3.7
msrc
10 дней назад

FFC-DH Peer Validation Uses Attacker-Supplied q

CVSS3: 3.7
debian
около 2 месяцев назад

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X ...

CVSS3: 3.7
github
около 2 месяцев назад

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts. When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared. A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, l...

EPSS

Процентиль: 37%
0.00455
Низкий

3.7 Low

CVSS3