CVE-2023-24533 Information

Description

Multiplication of certain unreduced P-256 scalars produce incorrect results. There are no protocols known at this time that can be attacked due to this.

Reference

https://github.com/FiloSottile/nistec/commit/c58aa1223ccf3943513e1e661cebce95af137244 https://go.dev/issue/58647 https://pkg.go.dev/vuln/GO-2023-1595

Share on: