A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1990591 | patch third party advisory issue tracking |
https://access.redhat.com/security/cve/CVE-2021-3798 | third party advisory |
https://github.com/opencryptoki/opencryptoki/pull/402 | third party advisory patch |
https://github.com/opencryptoki/opencryptoki/commit/4e3b43c3d8844402c04a66b55c6c940f965109f0 | third party advisory patch |