A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade golang | Jul 15, 2017 | Jun 22, 2017 |
| Centos_linux | — | Upgrade golang-binUpgrade golang-docsUpgrade golang-testsUpgrade golang-miscUpgrade golangUpgrade golang-src | Aug 28, 2019 | Jul 6, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade golang-srcUpgrade golangUpgrade golang-bin | Nov 30, 2017 | Jul 6, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Jul 6, 2017 |
| Oracle_linux | — | Upgrade golang-binUpgrade golangUpgrade golang-docsUpgrade golang-miscUpgrade golang-testsUpgrade golang-src | Aug 9, 2017 | May 23, 2017 |
| Redhat_linux | — | Upgrade golang-srcUpgrade golang-miscUpgrade golang-docsUpgrade golang-binUpgrade golang-testsUpgrade golang | Aug 3, 2017 | Jun 22, 2017 |
| Suse | — | Upgrade docker-distribution-registryUpgrade goUpgrade runcUpgrade go-docUpgrade containerdUpgrade docker-libnetworkUpgrade docker | Jun 23, 2017 | Jun 22, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 6, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub