The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected.
The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .
CVSS Details
- CVSS 4.0 Base Score: 2.9 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:Amber)
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rclone | Jun 18, 2026 | Feb 24, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.4.12Upgrade Splunk Enterprise to version 10.0.7Upgrade Splunk Enterprise to version 10.4.0Upgrade Splunk Enterprise to version 9.3.13Upgrade Splunk Enterprise to version 10.2.4 | Jun 12, 2026 | Feb 24, 2026 |
| Suse | — | Upgrade encUpgrade git-bug-zsh-completionUpgrade rclone-zsh-completionUpgrade git-bugUpgrade rcloneUpgrade go-sendxmppUpgrade rclone-bash-completionUpgrade git-bug-fish-completionUpgrade git-bug-bash-completionUpgrade amazon-ssm-agent | Apr 28, 2026 | Mar 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub