Bug 1209091 (CVE-2023-24533) - VUL-0: CVE-2023-24533: go: multiplication of certain unreduced P-256 scalars produce incorrect results
Summary: VUL-0: CVE-2023-24533: go: multiplication of certain unreduced P-256 scalars ...
Status: RESOLVED FIXED
Alias: CVE-2023-24533
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Jeff Kowalczyk
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/359553/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-24533:3.7:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-03-09 08:43 UTC by Alexander Bergmann
Modified: 2024-07-22 15:09 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2023-03-09 08:43:26 UTC
CVE-2023-24533

Multiplication of certain unreduced P-256 scalars produce incorrect results.
There are no protocols known at this time that can be attacked due to this.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-24533
https://www.cve.org/CVERecord?id=CVE-2023-24533
https://github.com/FiloSottile/nistec/commit/c58aa1223ccf3943513e1e661cebce95af137244
https://go.dev/issue/58647
https://pkg.go.dev/vuln/GO-2023-1595
Comment 1 Alexander Bergmann 2024-07-22 15:09:56 UTC
Already fixed with the latest versions.