Lucene search

K
osvGoogleOSV:GO-2022-0435
HistoryMay 20, 2022 - 9:17 p.m.

Panic due to large inputs affecting P-256 curves in crypto/elliptic

2022-05-2021:17:46
Google
osv.dev
13

8.6 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.0%

A crafted scalar input longer than 32 bytes can cause P256().ScalarMult or P256().ScalarBaseMult to panic. Indirect uses through crypto/ecdsa and crypto/tls are unaffected. amd64, arm64, ppc64le, and s390x are unaffected.

CPENameOperatorVersion
stdliblt1.17.9
stdlibge1.18.0-0
stdliblt1.18.1