CVE-2024-58262 Information

Description

The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.

Reference

https://crates.io/crates/curve25519-dalek https://github.com/dalek-cryptography/curve25519-dalek/pull/659 https://rustsec.org/advisories/RUSTSEC-2024-0344.html

CNNVD-202507-3427 (Published: 2025-07-27)

Share on: