VDB
RHSA-2023:5947
RHSA-2023:5947
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in the crypto/internal/nistec golang library. The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars, such as a scalar larger than the order of the curve. This does not impact usages of crypto/ecdsa or crypto/ecdh.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | run-once-duration-override-operator/run-once-duration-override-operator-bundle@sha256:5e2f382d233fab6817da02d17459b3e6e8c16f0be58270221b66d87ce3d09cc6_amd64 as a component of RODOO 1.0 for RHEL 8 | run-once-duration-override-operator/run-once-duration-override-operator-bundle@sha256:5e2f382d233fab6817da02d17459b3e6e8c16f0be58270221b66d87ce3d09cc6_amd64, run-once-duration-override-operator/run-once-duration-override-operator-bundle@sha256:5e2f382d233fab6817da02d17459b3e6e8c16f0be58270221b66d87ce3d09cc6_amd64, run-once-duration-override-operator/run-once-duration-override-operator-bundle@sha256:5e2f382d233fab6817da02d17459b3e6e8c16f0be58270221b66d87ce3d09cc6_amd64 |
| Red Hat | run-once-duration-override-operator | |
| golang | Go | |
| Red Hat | run-once-duration-override-operator/run-once-duration-override-rhel8@sha256:70c5f120078cec9a22f2e754e5606ebe5d086e38aeb5fc9daac18fced6705f43_amd64 as a component of RODOO 1.0 for RHEL 8 | run-once-duration-override-operator/run-once-duration-override-rhel8@sha256:70c5f120078cec9a22f2e754e5606ebe5d086e38aeb5fc9daac18fced6705f43_amd64, *, run-once-duration-override-operator/run-once-duration-override-rhel8@sha256:70c5f120078cec9a22f2e754e5606ebe5d086e38aeb5fc9daac18fced6705f43_amd64 |
| Red Hat | run-once-duration-override-operator/run-once-duration-override-operator-rhel8@sha256:a43806835a54ea3c712e1cbb96cd7ff2cd0434912ae1cbc11b4f54524c15c40b_amd64 as a component of RODOO 1.0 for RHEL 8 | *, *, run-once-duration-override-operator/run-once-duration-override-operator-rhel8@sha256:a43806835a54ea3c712e1cbb96cd7ff2cd0434912ae1cbc11b4f54524c15c40b_amd64 |
| Red Hat | run-once-duration-override-operator/run-once-duration-override-rhel8@sha256:70c5f120078cec9a22f2e754e5606ebe5d086e38aeb5fc9daac18fced6705f43_amd64 as a component of RODOO 1.0 for RHEL 8 | run-once-duration-override-operator/run-once-duration-override-rhel8@sha256:70c5f120078cec9a22f2e754e5606ebe5d086e38aeb5fc9daac18fced6705f43_amd64, run-once-duration-override-operator/run-once-duration-override-rhel8@sha256:70c5f120078cec9a22f2e754e5606ebe5d086e38aeb5fc9daac18fced6705f43_amd64, run-once-duration-override-operator/run-once-duration-override-rhel8@sha256:70c5f120078cec9a22f2e754e5606ebe5d086e38aeb5fc9daac18fced6705f43_amd64 |
| Red Hat | run-once-duration-override-operator/run-once-duration-override-operator-rhel8@sha256:a43806835a54ea3c712e1cbb96cd7ff2cd0434912ae1cbc11b4f54524c15c40b_amd64 as a component of RODOO 1.0 for RHEL 8 | run-once-duration-override-operator/run-once-duration-override-operator-rhel8@sha256:a43806835a54ea3c712e1cbb96cd7ff2cd0434912ae1cbc11b4f54524c15c40b_amd64, *, run-once-duration-override-operator/run-once-duration-override-operator-rhel8@sha256:a43806835a54ea3c712e1cbb96cd7ff2cd0434912ae1cbc11b4f54524c15c40b_amd64 |
| Red Hat | run-once-duration-override-operator/run-once-duration-override-operator-bundle@sha256:5e2f382d233fab6817da02d17459b3e6e8c16f0be58270221b66d87ce3d09cc6_amd64 as a component of RODOO 1.0 for RHEL 8 | *, *, run-once-duration-override-operator/run-once-duration-override-operator-bundle@sha256:5e2f382d233fab6817da02d17459b3e6e8c16f0be58270221b66d87ce3d09cc6_amd64 |
Timeline
- Oct 26, 2023 CVE Published
- Apr 28, 2026 Distribution Patch
- Apr 28, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 6, 2026 Security Advisory
- May 8, 2026 Security Advisory
- May 10, 2026 Distribution Patch
- May 10, 2026 Security Advisory
- May 11, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2237777 issue
- https://access.redhat.com/security/cve/CVE-2023-29406 advisory
- https://groups.google.com/g/golang-announce/c/2q13H6LEEx0 advisory
- https://go.dev/issue/62197 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39322 advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://go.dev/cl/471255 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-24539 advisory
- https://go.dev/issue/59721 advisory
- https://access.redhat.com/security/cve/CVE-2023-44487 advisory
- https://access.redhat.com/security/cve/CVE-2023-24532 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-24532 advisory
- https://access.redhat.com/security/cve/CVE-2023-39319 advisory
- https://access.redhat.com/security/cve/CVE-2023-39321 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2196029 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2237776 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://go.dev/issue/59722 advisory
- https://access.redhat.com/security/cve/CVE-2023-29409 advisory
- https://groups.google.com/g/golang-announce/c/X0b6CsSAaYI/m/Efv5DbZ9AwAJ advisory
…and 64 more