Multiplication of certain unreduced P-256 scalars produce incorrect results. There are no protocols known at this time that can be attacked due to this.
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.
Link | Tags |
---|---|
https://go.dev/issue/58647 | patch issue tracking |
https://github.com/FiloSottile/nistec/commit/c58aa1223ccf3943513e1e661cebce95af137244 | patch |
https://pkg.go.dev/vuln/GO-2023-1595 | third party advisory |