CVE-2025-8556

LOW3.7EPSS 0.09%

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

發布日:2025/6/10修改日:2026/2/4
也稱為:GHSA-2x5j-vhc8-9cwmCGA-2w9c-phq9-xm8hGO-2025-3754

描述

### Impact The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security. Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve. ### Patches Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues. We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1LOW3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

參考連結(9)